HIGH
Social Web Suite – Social Media Auto Post, Social Media Auto Publish <= 4.1.11 - Directory Traversal to Arbitrary File Download
Published Oct 3, 2024
7.5
HIGHCVSS 3.1
EPSS 0.96%
Description
The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.1.11 via the download_log function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected products
- Vendor Dejanmarkovic Product Social Web Suite – Social Media Auto Post, Social Media Auto Publish Defaultunaffected
- Version 0StatusaffectedConstraints<=4.1.11
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Dejanmarkovic | Social Web Suite – Social Media Auto Post, Social Media Auto Publish | unaffected |
|
- < 4.1.12
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49118 Advisory
- https://plugins.trac.wordpress.org/browser/social-web-suite/trunk/includes/libs/class-socialwebsuite-log.php#L78 Product
- https://plugins.trac.wordpress.org/changeset/3155593/social-web-suite/trunk?old=3068377&old_path=%2Fsocial-web-suite%2Ftrunk Patch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/78ba132c-b5b4-4999-a0ec-67d17ae2857f?source=cve Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Oct 3, 2024
Updated Apr 8, 2026
Reserved Aug 30, 2024
Link CVE-2024-8352
CISA Vulnrichment
Updated Oct 3, 2024
ENISA EUVD
EUVD-2024-49118 Assigner Wordfence
Published Oct 3, 2024
Updated Apr 8, 2026
Exploited since n/a
Link EUVD-2024-49118