CVE-2024-44018
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 5, 2024
Updated: Oct 7, 2024
CWE ID 22
Summary
CVE-2024-44018 is a path traversal vulnerability affecting the Instant Chat Floating Button plugin for WordPress Websites. The flaw, which allows PHP Local File Inclusion, occurs due to improper limitation of a pathname. attackers can exploit this vulnerability by manipulating input to traverse restricted directories, potentially gaining unauthorized access to sensitive files. This issue affects versions of the plugin from n/a through 1.0.5. WordPress site administrators are advised to update the plugin as soon as a patch is available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.