What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AGILELOGIX Store Locator WordPress.This issue affects Store Locator WordPress: from n/a through 1.4.14.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AGILELOGIX Store Locator WordPress.This issue affects Store Locator WordPress: from n/a through 1.4.14.
Explanation of Vulnerability in Simple Terms
The Store Locator plugin for WordPress versions up to 1.4.14 contains a path traversal vulnerability that allows high-privileged users to cause a denial of service by accessing files outside the intended directory. The vulnerability requires administrator-level access and does not affect data confidentiality or integrity. Sites running affected versions should update to a patched release.
What an attacker can do
An administrator can trigger a denial of service by traversing the file system to access restricted files.
Potential impact on your site
An administrator account could be used to crash or disable your site by accessing files outside the plugin directory.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities