PT-2024-37545 · WordPress · Geo My Wp

Michael Dyrna

·

Published

2024-08-18

·

Updated

2024-08-23

·

CVE-2024-6330

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GEO my WP WordPress plugin versions prior to 4.5.0.2
Description The issue allows unauthenticated attackers to include arbitrary files in PHP's execution context, leading to Remote Code Execution. This can be exploited by including malicious files, potentially allowing attackers to execute arbitrary code on the affected system.
Recommendations For versions prior to 4.5.0.2, update to version 4.5.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2024-6330

Affected Products

Geo My Wp