CVE-2024-8104

HIGH

WP Extended <3.0.8 - Path Traversal

Title source: llm
STIX 2.1

Description

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.8 via the download_file_ajax function. This makes it possible for authenticated attackers, with subscriber access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

Scores

CVSS v3 8.8
EPSS 0.0096
EPSS Percentile 56.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
wpextended/The Ultimate WordPress Toolkit – WP Extended < 3.0.8
wpextended/wp_extended < 3.0.9
Published Sep 04, 2024
Tracked Since Feb 18, 2026