CVE-2024-53800 Details
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in rezgo Rezgo rezgo allows PHP Local File Inclusion.This issue affects Rezgo: from n/a through <= 4.17.
A local file inclusion vulnerability has been identified in the Rezgo WordPress plugin, affecting versions through 4.17. This vulnerability allows for improper control of filenames in include or require statements, which could be exploited to include local files from the server and display their contents. Such an exploitation could potentially lead to a complete takeover of the database, depending on the site's configuration.
Users of the Rezgo WordPress plugin should update to version 4.17.1 or later. Patchstack users can enable auto-updates for vulnerable plugins.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-98 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rezgo rezgo online booking | < 4.17.1 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 1, 2026 | CVE Modified | [email protected] |
| Sep 26, 2025 | Modified Analysis | [email protected] |
| Aug 27, 2025 | CVE Modified | CISA-ADP |
| Jun 20, 2025 | Initial Analysis | [email protected] |
| Jan 7, 2025 | New CVE Received | [email protected] |
| Jan 7, 2025 | CVE Modified | CISA-ADP |