CVE-2024-12066

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Dec 21, 2024
CWE ID 73

Summary

CVE-2024-12066 is a vulnerability affecting the SMSA Shipping plugin for WordPress. The issue lies in the insufficient file path validation within the smsa_delete_label() function, which is present in all versions up to 2.2. This flaw allows authenticated attackers with Subscriber-level access or higher to delete arbitrary files on the server. The deletion of specific files, such as wp-config.php, can lead to remote code execution, posing a significant security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share