CVE-2024-7419

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 7, 2025
Updated: Feb 11, 2025
CWE ID 94

Summary

CVE-2024-7419 is a Remote Code Execution vulnerability affecting the WP ALL Export Pro plugin for WordPress. Versions up to 1.9.1 are impacted, allowing unauthenticated attackers to inject arbitrary PHP code into custom export fields due to missing input validation and sanitization of user-supplied data. This vulnerability can lead to a complete site compromise, as the malicious code gets executed on the server during the export process. The vulnerability is exacerbated when custom export fields contain user-supplied data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share