PT-2025-10424 · WordPress · Smtp

Hoang Phuc Vo

+1

·

Published

2025-03-08

·

Updated

2025-03-13

·

CVE-2024-13908

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SMTP by BestWebSoft plugin for WordPress versions up to 1.1.9
Description The issue arises from missing file type validation in the save options function, allowing authenticated attackers with Administrator-level access and above to upload arbitrary files on the server, potentially enabling remote code execution.
Recommendations For versions up to 1.1.9, update to a version that includes a fix for the missing file type validation in the save options function to prevent arbitrary file uploads.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13908

Affected Products

Smtp