CVE · Medium

CVE-2024-2023 — Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager [folders] < 3.0.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2023 Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager [folders] < 3.0.1 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.3 < 3.0.1 3.0.1 2024-06-13

CVE-2024-2023

The Folders and Folders Pro plugins contain a directory traversal weakness affecting versions up to 3.0 and 3.0.2 respectively within the 'handle_folders_file_upload' function. Users with author-level permissions or higher can exploit this flaw to upload files to any location on the server. The vulnerability requires authentication but allows attackers to write arbitrary files outside intended directories.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.