CVE-2024-13011

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 10, 2025
CWE ID 434

Summary

CVE-2024-13011: The WP Foodbakery plugin for WordPress contains a vulnerability that allows unauthenticated attackers to upload arbitrary files due to insufficient file type validation in the 'upload_publisher_profile_image' function. This issue, existing in versions up to 4.7, poses a serious risk as successful exploitation may enable remote code execution. WordPress site owners using this plugin are advised to update to the latest version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share