4.3

CVE-2019-19983

Exploit

Fast Velocity Minify <= 2.7.6 - Full Path Disclosure

In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs to be enabled and an admin-ajax request needs to call the fastvelocity_min_files action.
Mögliche Gegenmaßnahme
Fast Velocity Minify: Update to version 2.7.7, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FastvelocityMinify SwPlatformwordpress Version < 2.7.7
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Fast Velocity Minify
Version *-2.7.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.16% 0.631
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:P/I:N/A:N
cve@mitre.org 4.3 2.8 1.4
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://wpvulndb.com/vulnerabilities/9914
Third Party Advisory
https://www.wordfence.com/blog/2019/10/medium-severity-vulnerability-patched-in-fast-velocity-minify-plugin/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/ea13aebb-c853-4828-8d7f-b607aa83b702
Third Party Advisory