CVE-2024-5599
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-5599 is a vulnerability affecting the FileOrganizer – Manage WordPress and Website Files plugin, used in all versions up to 1.0.7. The issue lies within the 'fileorganizer_ajax_handler' function, which leads to Sensitive Information Exposure. Unauthenticated attackers can exploit this vulnerability and extract sensitive data, including backups and other confidential information, if the files have been moved to the plugin's built-in Trash folder. Users are advised to update to the latest version of the plugin or consider alternative solutions to secure their WordPress websites.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- File Organizer
Affected Vendors
- Fileorganizer