{"id":"CVE-2026-77193","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-77193","summary":"The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it…","details":"The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.","published":"2026-09-24T09:17:07.877","modified":"2026-09-24T09:17:07.877","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://plugins.trac.wordpress.org/changeset/3662793/"},{"type":"WEB","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad266e0f-fc69-4550-b89c-c32ce1221ee4?source=cve"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-24T09:17:07.877"}}