CVE-2024-11270
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jan 8, 2025
Updated: Jan 17, 2025
CWE ID 862
Summary
CVE-2024-11270: The WordPress Webinar Plugin, specifically WebinarPress, contains a vulnerability that allows authenticated attackers with subscriber-level access or above to create arbitrary files. This issue results from a missing capability check on the 'sync-import-imgs' function and lack of file type validation in all versions up to 1.33.24. Successful exploitation can lead to remote code execution.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.