Impact
Infocob CRM Forms allows an attacker to craft a request that traverses directories and triggers a download of any file on the server. This path traversal flaw can lead to unauthorized disclosure of sensitive data, such as configuration files, logs, or credentials. The vulnerability is a classic instance of "Improper Limitation of a Pathname to a Restricted Directory" (CWE‑22).
Affected Systems
The affected product is the WordPress plugin Infocob CRM Forms created by James Laforge. All releases up to and including version 2.4.0 are vulnerable. WordPress sites that host the plugin in these versions are at risk.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation. The flaw is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated web user who can access the plugin’s form interface and supply a specially crafted path parameter. Successful exploitation would allow download of arbitrary files, compromising confidentiality and potentially providing information that could aid further attacks.
OpenCVE Enrichment
EUVD