CVE-2024-9939: WordPress File Upload <= 4.24.13 - Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfufiledownloader.php. This makes it possible for unauthenticated attackers to read files outside of the originally intended directory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9939?
CVE-2024-9939 is considered a high severity vulnerability due to its potential for unauthenticated access and data exposure.
How do I fix CVE-2024-9939?
To fix CVE-2024-9939, update the WordPress File Upload plugin to version 4.24.14 or later, which addresses this vulnerability.
What versions are affected by CVE-2024-9939?
CVE-2024-9939 affects all versions of the WordPress File Upload plugin up to and including version 4.24.13.
Can CVE-2024-9939 be exploited remotely?
Yes, CVE-2024-9939 can be exploited remotely by unauthenticated attackers.
What type of vulnerability is CVE-2024-9939?
CVE-2024-9939 is a path traversal vulnerability that allows attackers to read arbitrary files from the server.