CVE-2025-24677
CVSS 3.1 Score 9.9 of 10 (high)
Details
Published Feb 4, 2025
CWE ID 94
Summary
CVE-2025-24677 is a Code Injection vulnerability affecting the WPSpins Post/Page Copying Tool. The tool, used from an unknown version up to 2.0.3, permits Remote Code Inclusion due to improper control in the code generation process. This issue can potentially allow attackers to inject malicious code and gain unauthorized access to websites using the tool. Users are recommended to update to a secure version of the WPSpins Post/Page Copying Tool as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Correo