Loading HuntDB...

GHSA-wx55-4qhm-8qw2

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information including those belonging to other sites, for example in shared hosting environments.

Related CVEs

Key Information

GHSA ID
GHSA-wx55-4qhm-8qw2
Published
October 20, 2023 9:30 AM
Last Modified
April 4, 2024 8:50 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 13, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.