---
id: CVE-2020-37245
title: >-
  Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability
  in the Folder input field that allows attackers to access files outside the
  web root by injecting directory traversal sequences
summary: >-
  Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability
  in the Folder input field that allows attackers to access files outside the
  web root by injecting directory traversal sequences. Additionally, the plugin
  fails …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-79
published: '2026-05-16'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T10:10:00.263'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-37245'
references:
  - url: >-
      https://downloads.wordpress.org/plugin/digital-publications-by-supsystic.1.6.9.zip
    label: disclosure@vulncheck.com
  - url: 'https://supsystic.com/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/49542'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wordpress-plugin-supsystic-digital-publications-path-traversal-xss
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00495
epssPercentile: 0.40018
ingestedAt: '2026-09-29T10:31:36.290Z'
---

## Overview

Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequences. Additionally, the plugin fails to sanitize input fields in publication settings, allowing stored cross-site scripting attacks through script injection in parameters like Area Width and Publication Width that execute when publications are viewed or edited.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
