Unrated severityNVD Advisory· Published Apr 12, 2021· Updated Aug 3, 2024
Patreon WordPress < 1.7.0 - Unauthenticated Local File Disclosure
CVE-2021-24227
Description
The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attacker could leak important internal files like wp-config.php, which contains database credentials and cryptographic keys used in the generation of nonces and cookies.
Affected products
1- Range: 1.7.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jetpack.com/2021/03/26/vulnerabilities-found-in-patreon-wordpress-plugin/mitrex_refsource_MISC
- wpscan.com/vulnerability/f62df02d-7678-440f-84a1-ddbf09364016mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.