First published: Sat Aug 24 2024(Updated: )
The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Maxbuttons | <9.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6499 is classified as an information exposure vulnerability, allowing unauthenticated attackers to access sensitive path information.
To fix CVE-2024-6499, update the MaxButtons plugin to version 9.8.0 or later.
CVE-2024-6499 affects all versions of the MaxButtons plugin up to and including 9.7.8.
Yes, CVE-2024-6499 can be exploited remotely by unauthenticated attackers.
Attackers can obtain the full path to instances of the MaxButtons plugin, which may lead to further exploitation.