CVE-2024-11635
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-11635 is a critical vulnerability affecting the WordPress File Upload plugin. This issue, present in all versions up to 4.24.12, allows unauthenticated attackers to execute remote code on servers by exploiting the 'wfu_ABSPATH' cookie parameter. By manipulating this parameter, cybercriminals can bypass authentication and gain access to the server's backend, posing a significant risk to websites using this plugin. Website administrators are strongly urged to upgrade to the latest version of the WordPress File Upload plugin as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.