Record summary

CVE-2023-6592 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 16, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

FastDup

Default status: unaffected

CVE ListBefore 2.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress FastDup <= 2.1.9 Sensitive Information Exposure - Directory ListingCVSS 5.3

FastDup WordPress plugin < 2.2 contains a directory listing vulnerability caused by lack of access restrictions in sensitive directories, letting attackers view export files, exploit requires no authentication.

Impact

Attackers can access sensitive export files, potentially leading to information disclosure.

Remediation

Update to version 2.2 or later.

WeaknessesCWE-548
Authorspussycat0x
Template tagscvecve2023wordpresswp-pluginfastduplogwp
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Shodan: http.component:"WordPress"
FOFA: body="wp-content/njt-fastdup"
Google: inurl:"/wp-content/njt-fastdup/packages/" intitle:"Index of"

Source: ProjectDiscovery

References

3