plugin

Folders Pro Vulnerabilities

2 known security issues reported for the Folders Pro WordPress plugin. Most recent disclosed Jun 13, 2024.

1 high 1 medium

Running Folders Pro on your site? Check whether your installed version is affected.

Scan your site free

Folders <= 3.0 and Folders Pro <= 3.0.2 - Directory Traversal via handle_folders_file_upload

medium

The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0 in Folders and 3.0.2 in Folders Pro via the 'handle_folders_file_upload' function. This makes it possible for authenticated attackers, with author access and above, to upload files to arbitrar...

CVSS:
4.3
Affected:
up to 3.0.2
Fixed in:
3.0.3
Disclosed:
Jun 13, 2024

CVE-2024-2023 on NVD →

Folders Pro <= 3.0.2 - Authenticated(Author+) Arbitrary File Upload via handle_folders_file_upload

high

The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_folders_file_upload' function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author access and above, to upload arbitrary files on the af...

CVSS:
8.8
Affected:
up to 3.0.2
Fixed in:
3.0.3
Disclosed:
Jun 13, 2024

CVE-2024-2024 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database