CVE-2024-13791
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Published Feb 14, 2025
Updated: Feb 25, 2025
CWE ID 23
CWE ID 22
Summary
CVE-2024-13791 is a newly disclosed vulnerability in the Bit Assist plugin for WordPress. This issue allows authenticated attackers with Administrator-level access to traverse file paths through the plugin's downloadResponseFile() function. By exploiting this vulnerability, attackers can read the contents of arbitrary files on the server, potentially accessing sensitive information. Versions up to and including 1.5.2 of the plugin are affected. Users are strongly advised to update to the latest, secure version of the plugin to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share