CVE-2024-9047: WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfufiledownloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the targeted WordPress installation to be using PHP 7.4 or earlier.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9047?
CVE-2024-9047 is considered a high severity vulnerability due to its potential for unauthenticated file reading and deletion.
How do I fix CVE-2024-9047?
To fix CVE-2024-9047, update the WordPress File Upload plugin to version 4.24.12 or later.
Who is affected by CVE-2024-9047?
CVE-2024-9047 affects all versions of the WordPress File Upload plugin up to and including 4.24.11.
What attack vectors are associated with CVE-2024-9047?
CVE-2024-9047 allows unauthenticated attackers to exploit path traversal vulnerabilities to access or delete files.
Is there a workaround for CVE-2024-9047 if I cannot update immediately?
If you cannot update immediately, consider disabling the WordPress File Upload plugin until a fix can be applied.