CVE-2024-8704

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Sep 26, 2024
Updated: Oct 1, 2024
CWE ID 22

Summary

CVE-2024-8704 is a vulnerability affecting the Advanced File Manager plugin for WordPress. It allows authenticated attackers with Administrator-level access to include and execute arbitrary files on the server through the 'fma_locale' parameter. This Local JavaScript File Inclusion vulnerability can result in bypassing access controls, obtaining sensitive data, or code execution, even in cases where only "safe" file types, such as images, can be uploaded and included. Versions up to and including 5.2.8 of the plugin are impacted.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share