CVE-2024-47637: WordPress LiteSpeed Cache plugin <= 6.4.1 - Path Traversal vulnerability
Published Oct 16, 2024
·Updated
Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.
Affected Software
3 affected components
Litespeedtech Litespeed Cache Wordpress<6.5.1
Litespeed Technologies LiteSpeed Cache>=n/a, <=6.4.1
Litespeed Technologies LiteSpeed Cache plugin for WordPress<=6.4.1
Remediation
Information
Update to 6.5.1 or a higher version.
Event History
Oct 16, 2024
CVE Published
via MITRE·01:12 PM
Data Sourced
via MITRE·01:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47637?
CVE-2024-47637 is considered a medium severity vulnerability due to the potential for unauthorized file access via path traversal.
2
How do I fix CVE-2024-47637?
To fix CVE-2024-47637, upgrade LiteSpeed Cache to version 6.4.2 or later, which addresses the path traversal issue.
3
Which versions of LiteSpeed Cache are affected by CVE-2024-47637?
CVE-2024-47637 affects LiteSpeed Cache version n/a through 6.4.1.
4
Is the LiteSpeed Cache plugin for WordPress vulnerable to CVE-2024-47637?
Yes, the LiteSpeed Cache plugin for WordPress is vulnerable to CVE-2024-47637 up to version 6.4.1.
5
What type of vulnerability is CVE-2024-47637?
CVE-2024-47637 is a relative path traversal vulnerability that allows unauthorized file access.