CVE-2024-56264

CVSS 3.1 Score 6.6 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 434

Summary

CVE-2024-56264 is a newly identified vulnerability affecting the Beee ACF City Selector plugin. This issue involves an Unrestricted File Upload vulnerability, permitting attackers to upload a dangerous type of file, such as a web shell, to a web server. The vulnerability exists in versions of ACF City Selector from n/a through 1.14.0, putting these installations at risk. Successful exploitation could result in unauthorized access, data theft, or server compromise. It is highly recommended that affected users immediately update to the latest version of the plugin to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share