CVE-2024-8756
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2024-8756 is a vulnerability affecting the Quform plugin for WordPress, which allows unauthenticated attackers to extract sensitive information, including Personally Identifiable Information, from uploaded files. This issue arises due to a flaw in the 'saveUploadedFile' function and is present in all versions up to 2.20.0. Even after upgrading to a patched version, previously uploaded files remain vulnerable, necessitating the deletion and recreation of affected forms and files. To mitigate this risk, site administrators are advised to download any sensitive files, delete existing ones, and recreate forms after upgrading to version 2.21.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.