CVE-2024-13908: SMTP by BestWebSoft <= 1.1.9 - Authenticated (Administrator+) Arbitrary File Upload
The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'saveoptions' function in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13908?
CVE-2024-13908 is classified with a high severity due to the potential for arbitrary file uploads.
How do I fix CVE-2024-13908?
To fix CVE-2024-13908, update the BestWebSoft SMTP plugin to version 1.2.0 or later.
Who is affected by CVE-2024-13908?
Authenticated users with Administrator-level access on WordPress sites running versions up to 1.1.9 of the BestWebSoft SMTP plugin are affected by CVE-2024-13908.
What capabilities does the CVE-2024-13908 vulnerability provide to attackers?
CVE-2024-13908 allows authenticated attackers to upload arbitrary files, potentially leading to further exploitation.
When was CVE-2024-13908 disclosed?
CVE-2024-13908 was disclosed in the context of vulnerability reports in early 2024.