PT-2024-39204 · WordPress · Advanced File Manager Shortcodes+1

Siunam

+1

·

Published

2024-09-26

·

Updated

2024-10-01

·

CVE-2024-8725

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: WordPress (affected versions not specified)
Description: The issue is due to a lack of proper checks, allowing lower-privileged roles to upload .css and .js files to arbitrary directories. This enables authenticated attackers with Subscriber-level access and above, granted permissions by an administrator, to upload .css and .js files to any directory within the WordPress root directory, potentially leading to Stored Cross-Site Scripting. The Advanced File Manager Shortcodes plugin must be installed to exploit this issue.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-8725

Affected Products

Advanced File Manager Shortcodes
Wordpress