The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.0 via the content/downloader.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Please note the vendor released the patched version as the same version as the affected version.
History

Tue, 26 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Fwdesign
Fwdesign mp3 Sticky Player
CPEs cpe:2.3:a:fwdesign:mp3_sticky_player:*:*:*:*:*:*:*:*
Vendors & Products Fwdesign
Fwdesign mp3 Sticky Player
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 23 Nov 2024 07:45:00 +0000

Type Values Removed Values Added
Description The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.0 via the content/downloader.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Please note the vendor released the patched version as the same version as the affected version.
Title MP3 Sticky Player <= 8.0 - Unauthenticated Arbitrary File Read/Download
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-11-26T16:31:04.149Z

Reserved: 2024-11-04T16:59:29.662Z

Link: CVE-2024-10803

cve-icon Vulnrichment

Updated: 2024-11-26T16:30:54.876Z

cve-icon NVD

Status : Received

Published: 2024-11-23T08:15:03.413

Modified: 2024-11-23T08:15:03.413

Link: CVE-2024-10803

cve-icon Redhat

No data.