CVE Database /
CVE-2024-2023
CVE · Medium
CVE-2024-2023 — Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager [folders] < 3.0.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-2023
|
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager [folders] < 3.0.1 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Medium
4.3
|
< 3.0.1
|
3.0.1 |
2024-06-13 |
—
|
CVE-2024-2023
The Folders and Folders Pro plugins contain a directory traversal weakness affecting versions up to 3.0 and 3.0.2 respectively within the 'handle_folders_file_upload' function. Users with author-level permissions or higher can exploit this flaw to upload files to any location on the server. The vulnerability requires authentication but allows attackers to write arbitrary files outside intended directories.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings