NA

CVE-2024-0380

Published: 05/02/2024 Updated: 07/02/2024
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8

Vulnerability Summary

The WP Recipe Maker plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 9.1.0 via the 'icon' attribute used in Shortcodes. This makes it possible for authenticated attackers, with contributor-level access and above, to include the contents of SVG files on the server, which can be leveraged for Cross-Site Scripting.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bootstrapped wp recipe maker