CVE-2024-24714: WordPress Icons Font Loader Plugin <= 1.1.4 is vulnerable to Arbitrary File Upload
Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons Font Loader: from n/a through 1.1.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
bPlugins LLC Icons Font Loader / WordPress Icons Font Loader Pluginto a version that resolves this vulnerability.Fixed in 1.1.5
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24714?
CVE-2024-24714 is classified as a high severity vulnerability due to its potential for unrestricted file uploads.
How do I fix CVE-2024-24714?
To fix CVE-2024-24714, update the Icons Font Loader plugin to a version later than 1.1.4.
Who is affected by CVE-2024-24714?
CVE-2024-24714 affects users of bPlugins LLC Icons Font Loader versions up to and including 1.1.4.
What type of vulnerability is CVE-2024-24714?
CVE-2024-24714 is an Unrestricted Upload of File with Dangerous Type vulnerability.
What are the risks associated with CVE-2024-24714?
The risks of CVE-2024-24714 include potential unauthorized access and execution of malicious files on the affected systems.