CVE-2024-8756

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Nov 9, 2024
Updated: Nov 12, 2024
CWE ID 200

Summary

CVE-2024-8756 is a vulnerability affecting the Quform plugin for WordPress, which allows unauthenticated attackers to extract sensitive information, including Personally Identifiable Information, from uploaded files. This issue arises due to a flaw in the 'saveUploadedFile' function and is present in all versions up to 2.20.0. Even after upgrading to a patched version, previously uploaded files remain vulnerable, necessitating the deletion and recreation of affected forms and files. To mitigate this risk, site administrators are advised to download any sensitive files, delete existing ones, and recreate forms after upgrading to version 2.21.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share