CVE-2024-4551

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Jun 15, 2024
Updated: Jun 17, 2024

Summary

CVE-2024-4551 is a local file inclusion vulnerability affecting the Video Gallery – YouTube Playlist and Channel Gallery plugin for WordPress. The issue lies within the display function in all versions up to 1.3.13. This flaw grants authenticated attackers, including contributors and higher, the ability to include and execute arbitrary PHP files on the server. Consequently, attackers can bypass access controls, obtain sensitive data, or execute code, posing a significant security risk, especially when "safe" file types can be uploaded and included.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-4551 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions