← Back to browse · API

CVE-2024-27954

Severity
CRITICAL
CVSS
9.3
EPSS
0.72953
Risk score
62.73
CISA KEV
No
PoC
No
Published
2024-05-17
Modified
2026-04-28
First seen
2026-08-07
Aliases
EUVD-2024-25128, GHSA-CJR8-GJ3H-WPFP
Products
ValvePress:Automatic n/a ≤3.92.0
Sources
euvd EUVD-2024-25128

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.

References