CVE-2024-13091

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 22, 2025
CWE ID 434

Summary

CVE-2024-13091: Unauthenticated attackers can exploit the WPBot Pro Wordpress Chatbot plugin's missing file type validation in the 'qcld_wpcfb_file_upload' function, leading to arbitrary file uploads. Versions up to 13.5.4 are affected. Successful exploitation may enable remote code execution, with the requirement of the ChatBot Conversational Forms plugin and the Conversational Form Builder Pro addon.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share