CVE-2024-47324 HIGH

CVE-2024-47324: WordPress WP Timeline plugin <= 3.6.7 - Local File Inclusion vulnerability

Vendor Ex-Themes
Product WP Timeline – Vertical and Horizontal timeline plugin
Weakness CWE-35
Published October 5, 2024
Last update April 28, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Path Traversal: '.../...//' vulnerability in Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin wp-timelines.This issue affects WP Timeline – Vertical and Horizontal timeline plugin: from n/a through <= 3.6.7.

Explanation of Vulnerability in Simple Terms

02Summary

The WP Timeline plugin for WordPress contains a vulnerability that allows authenticated users with low privileges to read sensitive data, modify site content, or disrupt service. The flaw requires network access and some technical setup to exploit, but does not require user interaction. All versions up to 3.6.7 are affected.

What an attacker can do

03Attacker Capabilities

Read sensitive data, modify content, or disrupt the site's availability.

Potential impact on your site

04Site Impact

A logged-in user with basic permissions could compromise data confidentiality, alter site content, or cause downtime.

Conditions required to exploit

05Prerequisites

Attacker must be authenticated with low-level user privileges and have network access.

Key dates

06Disclosure timeline

October 5, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE