What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Web-Settler Landing Page Builder – Free Landing Page Templates allows Path Traversal.This issue affects Landing Page Builder – Free Landing Page Templates: from n/a through 3.1.9.9.
Explanation of Vulnerability in Simple Terms
02Summary
An authenticated administrator can read arbitrary files from the server by manipulating file paths in requests to the Landing Page Builder plugin. The vulnerability exploits insufficient path validation, allowing access to sensitive files outside the intended directory. This affects versions up to 3.1.9.9. No user interaction is required once an admin account is compromised or available.
What an attacker can do
03Attacker Capabilities
Read arbitrary files from the server, including configuration files and other sensitive data.
Potential impact on your site
04Site Impact
An attacker with admin credentials can access sensitive files like wp-config.php, database backups, or private keys.
Conditions required to exploit
05Prerequisites
Administrator-level access to the WordPress site; network access to the plugin.
Key dates
06Disclosure timeline
May 17, 2024
CVE published
April 28, 2026
Record updated