The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.0 via the content/downloader.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Please note the vendor released the patched version as the same version as the affected version.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fwdesign
Fwdesign mp3 Sticky Player |
|
CPEs | cpe:2.3:a:fwdesign:mp3_sticky_player:*:*:*:*:*:*:*:* | |
Vendors & Products |
Fwdesign
Fwdesign mp3 Sticky Player |
|
Metrics |
ssvc
|
Sat, 23 Nov 2024 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.0 via the content/downloader.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Please note the vendor released the patched version as the same version as the affected version. | |
Title | MP3 Sticky Player <= 8.0 - Unauthenticated Arbitrary File Read/Download | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-11-26T16:31:04.149Z
Reserved: 2024-11-04T16:59:29.662Z
Link: CVE-2024-10803

Updated: 2024-11-26T16:30:54.876Z

Status : Received
Published: 2024-11-23T08:15:03.413
Modified: 2024-11-23T08:15:03.413
Link: CVE-2024-10803

No data.