The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing authorization and insufficient file path validation in the file-process.php in all versions up to, and including, 2.5.1. This makes it possible for unauthenticated attackers to delete the contents of arbitrary files on the server, which can break the site or lead to data loss.
History

Fri, 06 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Nsp-code
Nsp-code wp Hide \& Security Enhancer
CPEs cpe:2.3:a:nsp-code:wp_hide_\&_security_enhancer:*:*:*:*:*:wordpress:*:*
Vendors & Products Nsp-code
Nsp-code wp Hide \& Security Enhancer
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Dec 2024 05:45:00 +0000

Type Values Removed Values Added
Description The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing authorization and insufficient file path validation in the file-process.php in all versions up to, and including, 2.5.1. This makes it possible for unauthenticated attackers to delete the contents of arbitrary files on the server, which can break the site or lead to data loss.
Title WP Hide & Security Enhancer <= 2.5.1 - Missing Authorization to Unauthenticated Arbitrary File Contents Deletion
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-12-06T05:26:15.076Z

Updated: 2024-12-06T16:10:30.516Z

Reserved: 2024-11-20T23:17:39.897Z

Link: CVE-2024-11585

cve-icon Vulnrichment

Updated: 2024-12-06T16:09:56.949Z

cve-icon NVD

Status : Received

Published: 2024-12-06T06:15:22.723

Modified: 2024-12-06T06:15:22.723

Link: CVE-2024-11585

cve-icon Redhat

No data.