S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Mar 10, 2026

CVE-2024-9765 Scanner

CVE-2024-9765 Scanner - Path Traversal vulnerability in EKC Tournament Manager WordPress plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-9765
6.5
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
EKC Tournament Manager
AFFECTED< 2.2.2SAFE ✓≥ 2.2.2
Updated Aug 19, 2026View on NVD →
Detail

EKC Tournament Manager is a WordPress plugin used by tournament organizers to manage and display tournament brackets, participants, and results on their WordPress websites. It allows users to customize their tournament setup, handle participant data, and integrate with their existing WordPress site architecture easily. The plugin is popular among sports clubs and gaming communities for its functionality and ease of use. It serves as a comprehensive tool for managing various types of tournaments, offering both organizers and participants a digital platform for tournament management. Regular updates and features are added to enhance user experience and security. EKC Tournament Manager is maintained by lukashuser for WordPress users wanting to host tournaments efficiently.

Path Traversal is a vulnerability that occurs when input data isn't properly validated, allowing users to access directories and files outside the intended environment. In web applications, such vulnerabilities can be exploited through URL manipulation to access unauthorized files. This particular vulnerability impacts the EKC Tournament Manager WordPress plugin, allowing logged-in admin users to exploit path traversal through inadequate validation checks. The vulnerability is significant as it could potentially expose sensitive information contained in system files. Proper validation and sanitization of file paths are critical in mitigating such risks. Remediation typically involves updates to the plugin's code to enforce strict checking.

In this case, logged-in admin users are able to exploit a path traversal vulnerability by crafting a specific request to download arbitrary system files. The vulnerable endpoint is accessible through the URL path leading to the plugin admin page, where inadequate handling of file paths allows such exploitation. The primary parameter being exploited is associated with the backup download action, where directory traversal sequences are used to access restricted files. This vulnerability arises due to the lack of adequate security controls in the file handling mechanism of the plugin. Consequently, sensitive files such as /etc/passwd can be accessed.

If this vulnerability is exploited by malicious entities, it can lead to significant security breaches. Exploitability by authorized admin users can result in unauthorized access to system files leading to leakage of sensitive data such as configuration and password files. Attackers could leverage this information for further attacks, including privilege escalation or data manipulation. The overall impact on organizational trust and data integrity could be severe, potentially causing loss of confidential information and service disruptions. Quick remediation is essential to restore security and prevent unauthorized access.

REFERENCES

Solution Advice
  • Upgrade to version 2.2.2 or later to address the path traversal vulnerability.
  • Enforce strict input validation and sanitization on file path parameters in the application.
  • Restrict admin user permissions to minimize potential damage from exploited vulnerabilities.
  • Implement access controls to monitor and limit access to sensitive files and directories.
  • Conduct regular security audits of plugins and their configurations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.