First published: Wed Apr 03 2024(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows Upload a Web Shell to a Web Server.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Themeisle Multiple Page Generator Plugin - MPG | <3.4.1 | |
Themeisle Multiple Page Generator Plugin | <=3.4.0 | |
WordPress Multiple Page Generator Plugin | <=3.4.0 |
Update to 3.4.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27951 is considered a critical vulnerability due to the potential for remote code execution.
To fix CVE-2024-27951, update the Multiple Page Generator Plugin to version 3.4.1 or later.
CVE-2024-27951 is classified as an Unrestricted Upload of File with Dangerous Type vulnerability.
CVE-2024-27951 affects the Multiple Page Generator Plugin versions from n/a up to 3.4.0.
If exploited, CVE-2024-27951 can allow attackers to upload a web shell to your server, compromising its security.