CVE-2024-44034
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-44034 is a newly disclosed vulnerability that affects WPSPX, a WordPress plugin used for creating pop-ups and subscription forms. The weakness, classified as an improper limitation of a pathname to a restricted directory, enables PHP Local File Inclusion. An attacker exploiting this path traversal vulnerability can manipulate file paths to gain unauthorized access to sensitive files on impacted systems. WPSPX versions from n/a through 1.0.2 are known to be vulnerable to this issue. Users should update their WordPress installations and plugins immediately to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.