The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/538c875f-4c20-4be0-8098-5bddb7aecff4/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
16 Jul 2024, 18:10
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CPE | cpe:2.3:a:elearningfreak:insert_or_embed_articulate_content:*:*:*:*:*:wordpress:*:* | |
First Time |
Elearningfreak insert Or Embed Articulate Content
Elearningfreak |
|
CWE | CWE-434 | |
References | () https://wpscan.com/vulnerability/538c875f-4c20-4be0-8098-5bddb7aecff4/ - Exploit, Third Party Advisory |
15 Jul 2024, 13:00
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Jul 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-15 06:15
Updated : 2024-08-01 13:59
NVD link : CVE-2024-5630
Mitre link : CVE-2024-5630
CVE.ORG link : CVE-2024-5630
JSON object : View
Products Affected
elearningfreak
- insert_or_embed_articulate_content
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type