CVE-2024-13011
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 10, 2025
CWE ID 434
Summary
CVE-2024-13011: The WP Foodbakery plugin for WordPress contains a vulnerability that allows unauthenticated attackers to upload arbitrary files due to insufficient file type validation in the 'upload_publisher_profile_image' function. This issue, existing in versions up to 4.7, poses a serious risk as successful exploitation may enable remote code execution. WordPress site owners using this plugin are advised to update to the latest version to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share