The ABC Notation plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.3 via the 'file' attribute of the 'abcjs' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
History

Tue, 04 Feb 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Paulrosen
Paulrosen abc Notation
CPEs cpe:2.3:a:paulrosen:abc_notation:*:*:*:*:*:wordpress:*:*
Vendors & Products Paulrosen
Paulrosen abc Notation

Mon, 27 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 25 Jan 2025 07:30:00 +0000

Type Values Removed Values Added
Description The ABC Notation plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.3 via the 'file' attribute of the 'abcjs' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Title ABC Notation <= 6.1.3 - Authenticated (Contributor+) Arbitrary File Read
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-01-25T07:24:19.540Z

Updated: 2025-01-27T15:36:39.255Z

Reserved: 2025-01-20T20:26:50.579Z

Link: CVE-2024-13550

cve-icon Vulnrichment

Updated: 2025-01-27T15:36:31.244Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-25T08:15:09.847

Modified: 2025-02-04T19:25:13.807

Link: CVE-2024-13550

cve-icon Redhat

No data.