CVE-2024-56214
CVSS 3.1 Score 8.3 of 10 (high)
Details
Published Dec 31, 2024
CWE ID 35
Summary
CVE-2024-56214 is a newly disclosed path traversal vulnerability that affects Userpro, a plugin used by DeluxeThemes, from version n/a through 5.1.9. An attacker can exploit this issue by manipulating a file path to traverse directories outside of the intended location, potentially gaining unauthorized access to sensitive information or executing malicious code. This vulnerability poses a significant risk to websites utilizing the affected plugin and requires immediate attention from administrators for patching or mitigation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.