CVE-2024-10803

HIGH

MP3 Sticky Player <8.0 - Path Traversal

Title source: llm
STIX 2.1

Description

The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.0 via the content/downloader.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Please note the vendor released the patched version as the same version as the affected version.

Scores

CVSS v3 7.5
EPSS 0.0093
EPSS Percentile 55.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
FWDesign/MP3 Sticky Player < 8.0
Published Nov 23, 2024
Tracked Since Feb 18, 2026