Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-4936

Опубликовано: 14 июн. 2024
Источник: nvd
CVSS3: 9.8
EPSS Средний

Описание

The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. This required allow_url_include to be enabled on the target site in order to exploit.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:canto:canto:*:*:*:*:*:wordpress:*:*
Версия до 3.0.9 (исключая)

EPSS

Процентиль: 95%
0.15983
Средний

9.8 Critical

CVSS3

Дефекты

NVD-CWE-Other

Связанные уязвимости

CVSS3: 9.8
github
больше 1 года назад

The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. This required allow_url_include to be enabled on the target site in order to exploit.

EPSS

Процентиль: 95%
0.15983
Средний

9.8 Critical

CVSS3

Дефекты

NVD-CWE-Other