CVE-2024-25913: WordPress MoveTo Plugin <= 6.2 is vulnerable to Arbitrary File Upload
Published Feb 26, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.
Affected Software
3 affected components
Skymoonlabs MoveTo<6.2
WordPress MoveTo Plugin<6.2
Skymoonlabs MoveTo<=6.2
Event History
Feb 26, 2024
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:27 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25913?
CVE-2024-25913 is considered a high severity vulnerability due to the potential for unrestricted file uploads.
2
How do I fix CVE-2024-25913?
To fix CVE-2024-25913, update the Skymoonlabs MoveTo plugin to the latest version beyond 6.2.
3
What is the impact of CVE-2024-25913?
The impact of CVE-2024-25913 allows for the upload of files with dangerous types, which could lead to code execution.
4
Which versions are affected by CVE-2024-25913?
CVE-2024-25913 affects Skymoonlabs MoveTo and WordPress MoveTo Plugin versions up to and including 6.2.
5
Who is the vendor for CVE-2024-25913?
The vendor for CVE-2024-25913 is Skymoonlabs, associated with the MoveTo product.