CVE-2024-1311: Brizy – Page Builder <= 2.4.40 - Authenticated (Contributor+) Arbitrary File Upload
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function in all versions up to, and including, 2.4.40. This makes it possible for authenticated attackers, with contributor access or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1311?
CVE-2024-1311 is classified as a critical vulnerability due to the potential for arbitrary file uploads.
How do I fix CVE-2024-1311?
To fix CVE-2024-1311, update the Brizy Page Builder plugin to version 2.4.41 or higher.
Who is affected by CVE-2024-1311?
CVE-2024-1311 affects authenticated users with contributor access or above on sites running Brizy Page Builder plugin versions up to 2.4.40.
What potential impact does CVE-2024-1311 have on websites?
CVE-2024-1311 allows authenticated attackers to upload potentially malicious files, leading to possible website compromises.
Is CVE-2024-1311 present in previous versions of the Brizy Page Builder plugin?
Yes, CVE-2024-1311 is present in all versions of the Brizy Page Builder plugin up to and including 2.4.40.