PT-2024-37569 · Wbw · The Product Table

Foxyyy

+1

·

Published

2024-07-08

·

Updated

2024-07-10

·

CVE-2024-6365

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Product Table by WBW plugin for WordPress version 2.0.1 and earlier
Description The issue is related to Remote Code Execution due to missing authorization and lack of sanitization of appended data in the languages/customTitle.php file. This allows unauthenticated attackers to execute code on the server via the saveCustomTitle function.
Recommendations For versions up to and including 2.0.1, consider disabling the saveCustomTitle function until a patch is available to prevent exploitation. Restrict access to the languages/customTitle.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-6365

Affected Products

The Product Table