← back
CVE-2023-6065

Quttera Web Malware Scanner < 3.4.2.1 - Directory Listing to Sensitive Data Exposure

EPSS 18.7%
Vexday Risk Score
23Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS EPSS 18.7%KEV nãoPoC Nuclei simMetasploit Patch
Lifecycle
18 Dec 2023Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →