Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-13418

Опубликовано: 02 мая 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files that can make remote code execution possible. This issue was escalated to Envato over two months from the date of this disclosure and the issue, while partially patched, is still vulnerable.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:g5plus:april:*:*:*:*:*:wordpress:*:*
Версия до 5.1 (включая)
cpe:2.3:a:g5plus:auteur:*:*:*:*:*:wordpress:*:*
Версия до 7.1 (включая)
cpe:2.3:a:g5plus:benaa:*:*:*:*:*:wordpress:*:*
Версия до 4.0.0 (включая)
cpe:2.3:a:g5plus:beyot:*:*:*:*:*:wordpress:*:*
Версия до 6.0.6 (включая)

EPSS

Процентиль: 66%
0.00506
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
github
9 месяцев назад

Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files that can make remote code execution possible. This issue was escalated to Envato over two months from the date of this disclosure and the issue, while partially patched, is still vulnerable.

EPSS

Процентиль: 66%
0.00506
Низкий

8.8 High

CVSS3

Дефекты

CWE-434