Ver todas as ameaças

CVE-2024-13418

Alvo: Não informado

Descrição

Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files that can make remote code execution possible. This issue was escalated to Envato over two months from the date of this disclosure and the issue, while partially patched, is still vulnerable.

Software
Não informado
Tipo Software
Plugin
CVE
CVE-2024-13418
Tags
Nâo informado
Data de publicação
02/05/2025
Última atualização
07/05/2025
Pontuação em CVSS 3.0
8.8
Alto
Rolar para cima