PT-2024-33470 · Vivek Tamrakar · Wp Rest Api Fns

Stealthcopter

·

Published

2024-10-20

·

Updated

2024-10-24

·

CVE-2024-49329

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vivek Tamrakar WP REST API FNS versions 1.0.0 and earlier
Description The issue allows attackers to upload harmful content, including web shells, to a web server due to an Unrestricted Upload of File with Dangerous Type vulnerability. This can be exploited by uploading a web shell, which could lead to further malicious activities.
Recommendations For versions 1.0.0 and earlier, update to version 1.0.1 to resolve the issue. As a temporary workaround, consider restricting access to the upload functionality until the update is applied.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-49329

Affected Products

Wp Rest Api Fns