PT-2024-39947 · WordPress · Wux Blog Editor

István Márton

·

Published

2024-10-26

·

Updated

2026-01-30

·

CVE-2024-9932

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wux Blog Editor plugin for WordPress versions up to and including 3.0.0
Description The Wux Blog Editor plugin for WordPress is susceptible to arbitrary file uploads due to inadequate file type validation within the wuxbt insertImageNew function. This allows unauthenticated attackers to upload arbitrary files to the affected server, potentially leading to remote code execution. The wuxbt insertImageNew function is the specific component with the identified flaw. Exploitation involves uploading malicious files through the system, which could then be executed on the server.
Recommendations Versions up to and including 3.0.0 should be updated to a newer, secure version if available. As a temporary workaround, consider restricting access to the wuxbt insertImageNew function until a patch is available.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-9932

Affected Products

Wux Blog Editor