CVE-2024-7426
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Sep 25, 2024
Updated: Sep 30, 2024
CWE ID 209
CWE ID 200
Summary
CVE-2024-7426 is a vulnerability affecting the Community by PeepSo plugin for WordPress. In versions up to 6.4.6.0, the plugin exposes the full path of the web application through errors that allow direct access to the sse.php file. Unauthenticated attackers can exploit this Full Path Disclosure vulnerability to retrieve sensitive information about the web application. However, the information obtained alone is not harmful and requires another vulnerability to inflict damage on an affected website.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.