PT-2024-37621 · WordPress · Media.Net Ads Manager

István Márton

·

Published

2024-07-27

·

Updated

2024-07-29

·

CVE-2024-6431

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Media.net Ads Manager plugin for WordPress versions up to, and including, 2.10.13
Description The issue arises from missing file type validation and a missing capability check in the sendMail function, allowing authenticated attackers with subscriber-level and above permissions to upload arbitrary files on the server. This could potentially lead to remote code execution. The vulnerability is only exploitable if someone has logged in through the API.
Recommendations For versions up to, and including, 2.10.13, update to a version that includes a fix for the missing file type validation and capability check in the sendMail function to prevent arbitrary file uploads. As a temporary workaround, consider disabling the sendMail function until a patch is available.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-6431

Affected Products

Media.Net Ads Manager