WordPress Aeroscroll Gallery Directory Traversal Vulnerability
Vulnerability
A directory traversal vulnerability has been identified in the WordPress Aeroscroll Gallery plugin, specifically in versions through 1.0.12. This vulnerability allows for path traversal, which could enable a malicious actor to access files outside of the intended directory, potentially leading to the exploitation of other weaknesses within the system.
Impact
Exploitation of this vulnerability could allow unauthorized access to files on the server, including sensitive information, which could be used to exploit other vulnerabilities or weaknesses in the system.
Remediation
Users of the WordPress Aeroscroll Gallery plugin are advised to update to a version later than 1.0.12. For those unable to update immediately, Patchstack offers a virtual patch that can be applied to mitigate the vulnerability until an official update is available.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
