PT-2024-37536 · WordPress · Blox Page Builder

István Márton

·

Published

2024-08-06

·

Updated

2024-08-06

·

CVE-2024-6315

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Blox Page Builder plugin for WordPress versions up to, and including, 1.0.65
Description: The issue is related to missing file type validation in the handleUploadFile function, allowing authenticated attackers with contributor-level and above permissions to upload arbitrary files on the affected site's server. This could potentially lead to remote code execution.
Recommendations: For versions up to, and including, 1.0.65, update to a version that includes a fix for the missing file type validation in the handleUploadFile function. As a temporary workaround, consider restricting access to the handleUploadFile function to prevent arbitrary file uploads until a patch is available.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-6315

Affected Products

Blox Page Builder