CVE-2024-13568

The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via the 'fluent-support' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/fluent-support directory which can contain file attachments included in support tickets.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpmanageninja:fluent_support:*:*:*:*:*:wordpress:*:*

History

26 May 2025, 01:30

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Wpmanageninja fluent Support
Wpmanageninja
CPE cpe:2.3:a:wpmanageninja:fluent_support:*:*:*:*:*:wordpress:*:*
Summary
  • (es) El complemento Fluent Support – Helpdesk & Customer Support Ticket System para WordPress es vulnerable a la exposición de información confidencial en todas las versiones hasta la 1.8.5 incluida a través del directorio 'fluent-support'. Esto permite que atacantes no autenticados extraigan datos confidenciales almacenados de forma insegura en el directorio /wp-content/uploads/fluent-support, que puede contener archivos adjuntos incluidos en los tickets de soporte.
References () https://plugins.trac.wordpress.org/browser/fluent-support/trunk/app/Services/Includes/FileSystem.php - () https://plugins.trac.wordpress.org/browser/fluent-support/trunk/app/Services/Includes/FileSystem.php - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/17f40832-8ae5-443a-aa98-f0e61d1152cc?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/17f40832-8ae5-443a-aa98-f0e61d1152cc?source=cve - Third Party Advisory

01 Mar 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-01 05:15

Updated : 2025-05-26 01:30


NVD link : CVE-2024-13568

Mitre link : CVE-2024-13568

CVE.ORG link : CVE-2024-13568


JSON object : View

Products Affected

wpmanageninja

  • fluent_support
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo