CVE-2024-12066
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Dec 21, 2024
CWE ID 73
Summary
CVE-2024-12066 is a vulnerability affecting the SMSA Shipping plugin for WordPress. The issue lies in the insufficient file path validation within the smsa_delete_label() function, which is present in all versions up to 2.2. This flaw allows authenticated attackers with Subscriber-level access or higher to delete arbitrary files on the server. The deletion of specific files, such as wp-config.php, can lead to remote code execution, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.