CVE-2024-11270 - WordPress WebinarPress Arbitrary File Creation Vulnerability (Remote Code Execution)

CVE ID : CVE-2024-11270 Published : Jan. 8, 2025, 5:15 a.m. | 1 hour, 59 minutes ago Description : The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function and missing file type validation in all versions up to, and including, 1.33.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary files that can lead to remote code execution. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Jan 8, 2025 - 08:15
 0  0
CVE-2024-11270 - WordPress WebinarPress Arbitrary File Creation Vulnerability (Remote Code Execution)
CVE ID : CVE-2024-11270
Published : Jan. 8, 2025, 5:15 a.m. | 1 hour, 59 minutes ago
Description : The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function and missing file type validation in all versions up to, and including, 1.33.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary files that can lead to remote code execution.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...