CVE-2024-9234
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-9234: This vulnerability impacts the GutenKit plugin for WordPress, which is used for creating blocks, patterns, and templates in the Gutenberg Block Editor. The issue lies with the install_and_activate_plugin_from_external() function, found within all versions up to 2.1.0. An attacker can exploit this missing capability check to upload arbitrary files, disguised as plugins, via the install-active-plugin REST API endpoint. Consequently, unauthenticated attackers can install and activate malicious plugins or use the uploaded files for various nefarious purposes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.