CVE-2024-56264
CVSS 3.1 Score 6.6 of 10 (medium)
Details
Summary
CVE-2024-56264 is a newly identified vulnerability affecting the Beee ACF City Selector plugin. This issue involves an Unrestricted File Upload vulnerability, permitting attackers to upload a dangerous type of file, such as a web shell, to a web server. The vulnerability exists in versions of ACF City Selector from n/a through 1.14.0, putting these installations at risk. Successful exploitation could result in unauthorized access, data theft, or server compromise. It is highly recommended that affected users immediately update to the latest version of the plugin to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.