Cyber Posture

CVE-2024-49249

High

Published: 07 January 2025

Published
07 January 2025
Modified
23 April 2026
KEV Added
Patch
CVSS Score 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS Score 0.0030 52.9th percentile
Risk Priority 17 60% EPSS · 20% KEV · 20% CVSS

Description

Path Traversal: '.../...//' vulnerability in SMSA Express SMSA Shipping smsa-shipping-official allows Path Traversal.This issue affects SMSA Shipping: from n/a through <= 2.3.

Security Summary

CVE-2024-49249 is a path traversal vulnerability in the SMSA Express SMSA Shipping Official WordPress plugin (smsa-shipping-official), affecting all versions up to and including 2.3. The issue, triggered by the '.../...//' traversal pattern, enables unauthorized file access and is rated with a CVSS v3.1 base score of 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H), mapped to CWE-35.

Remote unauthenticated attackers can exploit this vulnerability over the network with low attack complexity and no user interaction required. Exploitation allows arbitrary file deletion on the affected WordPress server, leading to significant availability impacts across the scoped components due to the changed scope (S:C).

The Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/smsa-shipping-official/vulnerability/wordpress-smsa-shipping-plugin-2-3-arbitrary-file-deletion-vulnerability?_s_id=cve characterizes this as an arbitrary file deletion vulnerability in SMSA Shipping plugin versions up to 2.3, providing details for security practitioners to assess and address the risk.

Details

CWE(s)
CWE-35

References