Path traversal in the popup-more WordPress plugin
# Popup-more < 2.2.0 CVE-2024-0844
Path traversal in the popup-more WordPress plugin.
### Description
Vulnerable file location : /popup-more/classes/Ajax.php <br>
Link : https://wordpress.org/plugins/popup-more/#description <br>
Version : - < **2.2.0** <br>
Parameter: formKey <br>
Status: patched <br>
https://github.com/advisories/GHSA-wxfh-8hrr-vfjw
### Code snippet:
```php
require_once YPM_POPUP_CLASSES.'form/'.esc_attr($key).'Form.php';
```
### Proof of concept:

Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view