The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jurre De Klijn
Jurre De Klijn wux Blog Editor |
|
CPEs | cpe:2.3:a:jurre_de_klijn:wux_blog_editor:*:*:*:*:*:*:*:* | |
Vendors & Products |
Jurre De Klijn
Jurre De Klijn wux Blog Editor |
|
Metrics |
ssvc
|
Sat, 26 Oct 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. | |
Title | Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-26T01:58:37.557Z
Updated: 2024-10-28T19:30:54.474Z
Reserved: 2024-10-14T11:53:40.594Z
Link: CVE-2024-9932
Vulnrichment
Updated: 2024-10-28T19:30:50.314Z
NVD
Status : Awaiting Analysis
Published: 2024-10-26T03:15:04.980
Modified: 2024-10-28T13:58:09.230
Link: CVE-2024-9932
Redhat
No data.