PT-2025-2256 · WordPress · Wp Image Uploader

Colin Xu

·

Published

2025-01-30

·

Updated

2025-01-30

·

CVE-2024-13720

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Image Uploader plugin for WordPress version 1.0.1 and earlier
Description The issue is related to insufficient file path validation in the gky image uploader main function() function, allowing unauthenticated attackers to delete arbitrary files on the server. This can lead to remote code execution when a critical file, such as wp-config.php, is deleted.
Recommendations For WP Image Uploader plugin for WordPress version 1.0.1 and earlier, update to a version later than 1.0.1 to resolve the issue. As a temporary workaround, consider disabling the gky image uploader main function() function until a patch is available.

Fix

RCE

Path traversal

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-13720

Affected Products

Wp Image Uploader