CVE-2024-12300: AR for WordPress <= 7.3 - Missing Authorization to Unauthenticated Limited File Upload
The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing capability check on the setarfeaturedimage() function in all versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to upload php files leveraging a double extension attack. It's important to note the file is deleted immediately and double extension attacks only work on select servers making this unlikely to be successfully exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12300?
CVE-2024-12300 has a high severity rating due to the risk of unauthorized file uploads.
How do I fix CVE-2024-12300?
To mitigate CVE-2024-12300, users should update the AR for WordPress plugin to version 7.4 or higher.
Which versions of the AR for WordPress plugin are affected by CVE-2024-12300?
All versions of the AR for WordPress plugin up to and including version 7.3 are affected by CVE-2024-12300.
Can CVE-2024-12300 be exploited by authenticated users?
No, CVE-2024-12300 specifically allows unauthenticated attackers to exploit the vulnerability.
What kind of files can be uploaded due to CVE-2024-12300?
CVE-2024-12300 allows for unauthorized PHP file uploads, which can lead to further compromise of the site.