Patreon WordPress < 1.7.0 - Local File Disclosure
2021-03-26 00:00
George StephanisStrategic Overview
StatusPatched in 1.7.0
Affected PluginPatreon WordPress
Affected Version
< 1.7.0CVSS7.5High
CVE
CVE-2021-24227Vulnerability Overview
The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attacker could leak important internal files like wp-config.php, which contains database credentials and cryptographic keys used in the generation of nonces and cookies.
Technical Analysis
REMEDIATION: Update to version 1.7.0, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C