Vulnerability Description
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Iptanus | Wordpress File Upload | < 4.24.15 |
Related Weaknesses (CWE)
References
- https://abrahack.com/posts/wp-file-upload-rce-part1/
- https://plugins.svn.wordpress.org/wp-file-upload/trunk/wfu_file_downloader.phpProduct
- https://www.wordfence.com/threat-intel/vulnerabilities/id/b5165f60-6515-4a2c-a12Third Party Advisory
FAQ
What is CVE-2024-11635?
CVE-2024-11635 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for u...
How severe is CVE-2024-11635?
CVE-2024-11635 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-11635?
Check the references section above for vendor advisories and patch information. Affected products include: Iptanus Wordpress File Upload.