CVE-2024-10672

CVSS 3.1 Score 2.7 of 10 (low)

Details

Published Nov 12, 2024
Updated: Nov 14, 2024
CWE ID 73
CWE ID 22

Summary

CVE-2024-10672 is a vulnerability affecting the Multiple Page Generator Plugin (MPG) for WordPress. This issue allows authenticated attackers with editor-level access or higher to delete limited files on the server due to insufficient file path validation in the mpg_upsert_project_source_block() function. Exploitation of this vulnerability can lead to data loss or unauthorized access, making it important for WordPress users to update their MPG plugin to a version beyond 4.0.2 to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Themeisle Multiple Page Generator

Affected Vendors

  • Themeisle