Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-7135

The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.173
EPSS Ranking 94.7%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-7135


Contact Us

Shodan ® - All rights reserved