CVE-2024-53739: WordPress Cryptocurrency Widgets For Elementor plugin <= 1.6.4 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cool Plugins Cryptocurrency Widgets For Elementor cryptocurrency-widgets-for-elementor allows PHP Local File Inclusion.This issue affects Cryptocurrency Widgets For Elementor: from n/a through <= 1.6.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53739?
CVE-2024-53739 is a medium severity vulnerability that allows for local file inclusion in the Cool Plugins Cryptocurrency Widgets For Elementor.
How do I fix CVE-2024-53739?
To fix CVE-2024-53739, update the Cryptocurrency Widgets For Elementor plugin to version 1.6.5 or later.
What types of attacks can CVE-2024-53739 enable?
CVE-2024-53739 can enable attackers to execute arbitrary PHP code or access sensitive files on the server.
Which versions are affected by CVE-2024-53739?
CVE-2024-53739 affects Cryptocurrency Widgets For Elementor versions up to and including 1.6.4.
Who is the vendor for CVE-2024-53739?
The vendor for CVE-2024-53739 is Cool Plugins, which develops the Cryptocurrency Widgets For Elementor plugin.