CVE-2024-27951: WordPress Multiple Page Generator Plugin <= 3.4.0 - Auth. Remote Code Execution (RCE) vulnerability
Published Apr 3, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows Upload a Web Shell to a Web Server.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.
Affected Software
3 affected components
Themeisle Multiple Page Generator Wordpress<3.4.1
Themeisle Multiple Page Generator Plugin<=3.4.0
WordPress Multiple Page Generator Plugin<=3.4.0
Remediation
Information
Update to 3.4.1 or a higher version.
Event History
Apr 3, 2024
CVE Published
via MITRE·11:53 AM
Data Sourced
via MITRE·11:53 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27951?
CVE-2024-27951 is considered a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2024-27951?
To fix CVE-2024-27951, update the Multiple Page Generator Plugin to version 3.4.1 or later.
3
What type of vulnerability is CVE-2024-27951?
CVE-2024-27951 is classified as an Unrestricted Upload of File with Dangerous Type vulnerability.
4
Which versions of the software are affected by CVE-2024-27951?
CVE-2024-27951 affects the Multiple Page Generator Plugin versions from n/a up to 3.4.0.
5
What impact can CVE-2024-27951 have on my website?
If exploited, CVE-2024-27951 can allow attackers to upload a web shell to your server, compromising its security.