CVE-2024-35162

Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server.
Configurations

No configuration.

History

21 Nov 2024, 09:19

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN85380030/ - () https://jvn.jp/en/jp/JVN85380030/ -
References () https://wordpress.org/plugins/download-plugins-dashboard/ - () https://wordpress.org/plugins/download-plugins-dashboard/ -

12 Aug 2024, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-22
Summary
  • (es) La vulnerabilidad de Path traversal existe en las versiones de Download Plugins and Themes from Dashboard anteriores a la 1.8.6. Si se explota esta vulnerabilidad, un atacante remoto autenticado con privilegio "switch_themes" puede obtener archivos arbitrarios en el servidor.

22 May 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-22 06:15

Updated : 2024-11-21 09:19


NVD link : CVE-2024-35162

Mitre link : CVE-2024-35162

CVE.ORG link : CVE-2024-35162


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')