{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/eesy_id2wp--publish-indesign-html5--1.0.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:eesy:eesy_id2wp_publish_indesign_html5:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-77193"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["eesy_ID2WP – Publish InDesign HTML5 (\u003c= 1.0.3)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","wordpress","cve"],"_cs_type":"advisory","_cs_vendors":["eesy"],"content_html":"\u003cp\u003eThe eesy_ID2WP - Publish InDesign HTML5 plugin for WordPress is vulnerable to a path traversal vulnerability (CVE-2026-77193) affecting all versions up to and including 1.0.3. The vulnerability exists within the 'id2wp_path' parameter, which fails to properly sanitize user-provided input before using it to access files on the underlying server filesystem. An unauthenticated attacker can exploit this flaw by submitting crafted requests to the plugin to traverse directory structures, potentially reading sensitive configuration files, system files, or application source code. This vulnerability poses a significant risk to the confidentiality of the affected WordPress environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read arbitrary files on the web server. Depending on server configuration and file permissions, this can lead to the exposure of sensitive data including database credentials, wp-config.php files, system environment variables, and site content.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the eesy_ID2WP plugin to a version beyond 1.0.3 immediately.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to inspect the 'id2wp_path' parameter for directory traversal sequences such as '../' or '..%2f'.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for requests containing suspicious path traversal patterns targeting the plugin's endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T10:46:35Z","date_published":"2026-09-24T10:46:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-eesy-id2wp-path-traversal/","summary":"The eesy_ID2WP WordPress plugin contains a path traversal vulnerability (CVE-2026-77193) via the id2wp_path parameter, allowing unauthenticated attackers to read arbitrary files from the hosting server.","title":"Unauthenticated Path Traversal in eesy_ID2WP WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-eesy-id2wp-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Eesy_ID2WP – Publish InDesign HTML5 (\u003c= 1.0.3)","version":"https://jsonfeed.org/version/1.1"}