Impact
The vulnerability originates from a directory traversal flaw in the Jssor Slider plugin for WordPress, allowing unauthenticated attackers to read arbitrary files on the server by manipulating the 'url' request parameter. This flaw can lead to disclosure of sensitive information such as configuration files, credentials, or other confidential data embedded in the site’s file system. The weakness is classified as CWE-22, which signifies an insecure handling of file paths. The impact is a clear violation of confidentiality, with no direct effect on integrity or availability reported.
Affected Systems
Any WordPress installation using Jssor Slider version 3.1.24 or earlier is affected. The plugin, named "Jssor Slider by jssor.com", is integrated into WordPress sites via the WordPress plugin repository. No additional vendor or product variants are listed. All sites that have not upgraded beyond 3.1.24 remain vulnerable.
Risk and Exploitability
The CVSS score of 7.5 places the vulnerability in the High severity range, indicating significant risk to affected sites. The EPSS score of < 1% indicates a very low inherent exploitation probability, yet the lack of authentication requirements still permits the flaw to be abused, implying a realistic exploitation risk. The flaw is not listed in CISA’s KEV catalog, yet its impact on confidential data justifies prompt remediation.
OpenCVE Enrichment