8.8
CVE-2024-3849
- EPSS 0.54%
- Veröffentlicht 02.05.2024 17:15:31
- Zuletzt bearbeitet 21.11.2024 09:30:32
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Click to Chat – HoliThemes <= 3.35 - Authenticated (Contributor+) Local File Inclusion
The Click to Chat – HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.35. This makes it possible for authenticated attackers, with contributor access or above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Mögliche Gegenmaßnahme
Click to Chat – HoliThemes: Update to version 4.0, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Click to Chat – HoliThemes
Version
*-3.35
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerholithemes
≫
Produkt
Click to Chat – HoliThemes
Default Statusunaffected
Version <=
3.35
Version
*
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.54% | 0.666 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|