PT-2024-25704 · WordPress · Wp Staging

Haidv35

·

Published

2024-05-29

·

Updated

2026-05-10

·

CVE-2024-3412

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress versions up to, and including, 3.4.3
Description The issue is related to arbitrary file uploads due to missing file type validation in the wpstg processing AJAX action. This allows authenticated attackers with administrator-level access and above to upload arbitrary files on the affected site's server, potentially making remote code execution possible.
Recommendations For versions up to, and including, 3.4.3, update to a version that includes the necessary file type validation to prevent arbitrary file uploads. As a temporary workaround, consider restricting access to the wpstg processing AJAX action to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-3412

Affected Products

Wp Staging