← back
CVE-2024-0380

WP Recipe Maker <= 9.1.0 - Directory Traversal

CVSS 5.4 MEDIUMEPSS 0.8%CWE-22
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
05 Feb 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The WP Recipe Maker plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 9.1.0 via the 'icon' attribute used in Shortcodes. This makes it possible for authenticated attackers, with contributor-level access and above, to include the contents of SVG files on the server, which can be leveraged for Cross-Site Scripting.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →