PT-2024-35247 · Pushassist · Push Notifications For Wordpress

·

CVE-2024-52408

·

Published

2024-11-16

·

Updated

2024-11-21

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Push Notifications for WordPress by PushAssist versions 3.0.8 and earlier
Description The issue allows users to upload a web shell to a web server due to an unrestricted upload of file with dangerous type vulnerability. This enables arbitrary code execution. The estimated number of potentially affected devices is not specified.
Recommendations For versions 3.0.8 and earlier, update to version 3.0.9 to resolve the issue. As a temporary workaround, consider restricting access to the plugin until the update is applied.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-52408

Affected Products

Push Notifications For Wordpress