CVE-2024-11150

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Nov 13, 2024
CWE ID 22

Summary

CVE-2024-11150 is a vulnerability affecting the WordPress User Extra Fields plugin. This issue arises from insufficient file path validation in the delete_tmp_uploaded_file() function, which exists in all versions up to 16.6. Unauthenticated attackers can exploit this vulnerability to delete arbitrary files on the server, with the potential for serious consequences. In particular, deleting files such as wp-config.php can lead to remote code execution, allowing attackers to gain control of the WordPress installation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share