CVE-2024-56249
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Jan 2, 2025
CWE ID 434
Summary
CVE-2024-56249 is a newly disclosed vulnerability affecting WPMasterToolKit, a plugin used in WordPress websites. The issue involves an Unrestricted File Upload vulnerability, which enables attackers to upload a web shell to a web server. By exploiting this flaw, hackers can gain unauthorized access and control over the affected system. This vulnerability exists in WPMasterToolKit versions from n/a to 1.13.1, representing a significant threat to WordPress sites using this plugin. Immediate update to a patched version is recommended to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.