CVE-2024-13091
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 22, 2025
CWE ID 434
Summary
CVE-2024-13091: Unauthenticated attackers can exploit the WPBot Pro Wordpress Chatbot plugin's missing file type validation in the 'qcld_wpcfb_file_upload' function, leading to arbitrary file uploads. Versions up to 13.5.4 are affected. Successful exploitation may enable remote code execution, with the requirement of the ChatBot Conversational Forms plugin and the Conversational Form Builder Pro addon.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.