CVE-2023-32297Active Exploitation

LOWCVSS 9.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LWS LWS Affiliation allows PHP Local File Inclusion.This issue affects LWS Affiliation: from n/a through 2.2.6.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-18: 1Active Exploitation · 2026-03-18: 1Technical Details · 2026-03-18: 103-18
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • zerizeri(インフラエンジニア技術ブログ)@zerizerizeri_bl
    Active Exploitation

    2026/3/11 22:34に「IPアドレス:170.64.153.212(VirusTotalにて3製品検知)」からWordPressプラグインの脆弱性(CVE-2023-32297)を悪用したローカルファイルインクルージョン(LFI)攻撃を検知。 【脆弱性の概要】 https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/lws-affiliation/lws-affiliation-226-unauthenticated-remotelocal-file-inclusion#:~:text=Description,plugins.trac.wordpress.org #WAF #セキュリティ #脅威検知 https://t.co/q7GFe2JYD4

    Post summary

    An LFI attack exploiting CVE-2023-32297 was detected from IP 170.64.153.212, indicating active exploitation but no patch or PoC information was provided.

    00010111
    46 followersView on X

Explore more