CVE-2024-6330
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.
Affected (1)
Products: Geomywp: Geo My Wordpress
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.5.0.2 |
References (1)
Source: contact@wpscan.com
ExploitThird Party Advisory
Timeline
No history available yet.