Record summary

CVE-2024-9765 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 16, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

EKC Tournament Manager

Default status: unaffected

CVE ListBefore 2.2.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMEKC Tournament Manager WordPress plugin - Path TraversalCVSS 6.5

EKC Tournament Manager WordPress plugin < 2.2.2 contains a path traversal caused by insufficient validation, letting logged in admin users download system files outside the WordPress directory.

Impact

Logged in admin users can download arbitrary system files, potentially exposing sensitive information.

Remediation

Upgrade to version 2.2.2 or later.

AuthorsSourabh-Sahu
Template tagscvecve2024lukashuserekc-tournament-managerauthenticatedlfivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:lukashuser:ekc_tournament_manager:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2