CVE-2024-56278

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 94

Summary

CVE-2024-56278 is a critical Code Injection vulnerability affecting WP Ultimate Exporter, a plugin used for exporting WordPress content. An attacker can exploit this vulnerability to include remote files using PHP Remote File Inclusion. This issue exists in versions of WP Ultimate Exporter from n/a through 2.9.1 and poses a significant threat to WordPress sites using this plugin. Successful exploitation could result in unauthorized access, data theft, or other malicious activities. Users of WP Ultimate Exporter are advised to update to the latest version immediately to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share