CVE-2024-12544
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-12544 is a vulnerability affecting the SurveyJS: Drag & Drop WordPress Form Builder plugin. The issue lies in the missing capability check on the callback function of the SurveyJS_DeleteFile class present in all versions up to 1.12.17. This flaw enables authenticated attackers, with Subscriber-level access and above, to execute arbitrary file deletions on the server. Potentially vulnerable files, including wp-config.php, could lead to remote code execution, posing a significant security risk. The vulnerability remains unpatched in version 1.12.20, and it also persists as a Cross-Site Request Forgery threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.