CVE-2024-27957: WordPress Pie Register plugin <= 3.8.3.1 - Unauthenticated Arbitrary File Upload vulnerability
Published Mar 17, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1.
Affected Software
3 affected components
Pie Register Pie Register<=3.8.3.1
WordPress Pie Register plugin<=3.8.3.1
Genetechsolutions Pie Register Wordpress<3.8.3.3
Event History
Mar 17, 2024
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27957?
CVE-2024-27957 is classified as a critical vulnerability due to the potential for unrestricted file uploads, allowing attackers to execute malicious payloads.
2
How do I fix CVE-2024-27957?
To fix CVE-2024-27957, update the Pie Register plugin to version 3.8.3.2 or later immediately.
3
What are the consequences of CVE-2024-27957?
The consequences of CVE-2024-27957 include unauthorized access, data breaches, and potential full server compromise through malicious file uploads.
4
Which versions of Pie Register are affected by CVE-2024-27957?
CVE-2024-27957 affects all versions of Pie Register from n/a up to and including 3.8.3.1.
5
Is CVE-2024-27957 exploitable by unauthenticated users?
Yes, CVE-2024-27957 can be exploited by unauthenticated users, making it a significant security risk.