CVE-2024-9234

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 862

Summary

CVE-2024-9234: This vulnerability impacts the GutenKit plugin for WordPress, which is used for creating blocks, patterns, and templates in the Gutenberg Block Editor. The issue lies with the install_and_activate_plugin_from_external() function, found within all versions up to 2.1.0. An attacker can exploit this missing capability check to upload arbitrary files, disguised as plugins, via the install-active-plugin REST API endpoint. Consequently, unauthenticated attackers can install and activate malicious plugins or use the uploaded files for various nefarious purposes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share