PT-2024-38462 · WordPress · Bit File Manager

Siunam

+1

·

Published

2024-09-04

·

Updated

2024-09-11

·

CVE-2024-7627

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bit File Manager plugin for WordPress versions 6.0 through 6.5.5
Description The issue is related to Remote Code Execution. This occurs due to the plugin writing a temporary file to a publicly accessible directory before performing file validation, specifically through the checkSyntax function. This makes it possible for unauthenticated attackers to execute code on the server if an administrator has allowed Guest User read permissions.
Recommendations For versions 6.0 through 6.5.5, consider disabling the checkSyntax function as a temporary workaround until a patch is available. Restrict access to the plugin's functionality to minimize the risk of exploitation, especially if Guest User read permissions are enabled. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Code Injection

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2024-7627

Affected Products

Bit File Manager