CVE-2024-6828
EUVD-2024-4784223.07.2024, 02:15
The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct stored cross-site scripting attacks and, in some rare cases, when the wp_filesystem fails to initialize - to Remote Code Execution.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| redux | gutenberg_template_library_\&_redux_framework | 4.4.12 ≤ 𝑥 ≤ 4.4.17 | ADP |
Common Weakness Enumeration
References