# CVE-2024-32523

## Summary

- **CVE ID:** CVE-2024-32523
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L)
- **CWE:** CWE-22, CWE-98
- **Published:** May 17, 2024
- **Last Modified:** May 11, 2026

## Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EverPress Mailster allows PHP Local File Inclusion.This issue affects Mailster: from n/a through 4.0.6.

## Affected Products

- EverPress — Mailster (n/a)
- EverPress — Mailster (0)

## References

- [CNA](https://patchstack.com/database/vulnerability/mailster/wordpress-mailster-plugin-4-0-6-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve)
- [CNA](https://patchstack.com/database/Wordpress/Plugin/mailster/vulnerability/wordpress-mailster-plugin-4-0-6-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.75%
- **EPSS Percentile:** 76.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._