CVE-2024-56249

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Jan 2, 2025
CWE ID 434

Summary

CVE-2024-56249 is a newly disclosed vulnerability affecting WPMasterToolKit, a plugin used in WordPress websites. The issue involves an Unrestricted File Upload vulnerability, which enables attackers to upload a web shell to a web server. By exploiting this flaw, hackers can gain unauthorized access and control over the affected system. This vulnerability exists in WPMasterToolKit versions from n/a to 1.13.1, representing a significant threat to WordPress sites using this plugin. Immediate update to a patched version is recommended to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share