Patreon WordPress < 1.7.0 - Local File Disclosure

2021-03-26 00:00
George Stephanis

Strategic Overview

Status
Patched in 1.7.0
Affected PluginPatreon WordPress
Affected Version< 1.7.0
CVSS7.5High
CVECVE-2021-24227
View all Patreon WordPress vulnerabilities

Vulnerability Overview

The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attacker could leak important internal files like wp-config.php, which contains database credentials and cryptographic keys used in the generation of nonces and cookies.

Technical Analysis

REMEDIATION: Update to version 1.7.0, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C