CVE detail
CVE-2021-24549 — CVE-2021-24549
Published 2021-08-23 · Modified 2026-06-17 · Vendor aceide_project · Product aceide · Source nvd
MEDIUM
severity
CVSS-derived band
0.0157
EPSS probability
exploitation probability, 30d
73.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The AceIDE WordPress plugin through 2.6.2 does not sanitise or validate the user input which is appended to system paths before using it in various actions, such as to read arbitrary files from the server. This allows high privilege users such as administrator to access any file on the web server outside of the blog directory via a path traversal attack.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References