Description
The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.24.01.24 via the js/fallback.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33315 | The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.24.01.24 via the js/fallback.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. |
References
History
Wed, 13 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sodahead
Sodahead luna Radio Player |
|
| CPEs | cpe:2.3:a:sodahead:luna_radio_player:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sodahead
Sodahead luna Radio Player |
|
| Metrics |
ssvc
|
Wed, 13 Nov 2024 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.24.01.24 via the js/fallback.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. | |
| Title | LUNA RADIO PLAYER <= 6.24.01.24 - Unauthenticated Arbitrary File Read | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:53:18.805Z
Reserved: 2024-11-04T18:55:11.280Z
Link: CVE-2024-10816
Updated: 2024-11-13T15:36:42.793Z
Status : Deferred
Published: 2024-11-13T04:15:04.300
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-10816
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD