CVE-2024-29135: WordPress Tourfic plugin <= 2.11.15 - Arbitrary File Upload vulnerability
Published Mar 19, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.15.
Affected Software
3 affected components
Themefic Tourfic Wordpress<2.11.16
Tourfic Tourfic<=2.11.15
WordPress Tourfic plugin<=2.11.15
Remediation
Information
Update to 2.11.16 or a higher version.
Event History
Mar 19, 2024
CVE Published
via MITRE·01:51 PM
Data Sourced
via MITRE·01:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 25, 58296
Event
via MITRE·04:14 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-29135?
CVE-2024-29135 has a medium severity level due to its potential for unauthorized file uploads.
2
How do I fix CVE-2024-29135?
To fix CVE-2024-29135, update Tourfic to version 2.11.16 or later.
3
What are the risks associated with CVE-2024-29135?
The risks of CVE-2024-29135 include the possibility of malicious file uploads that could compromise the server.
4
Which versions of Tourfic are affected by CVE-2024-29135?
CVE-2024-29135 affects Tourfic versions from n/a through 2.11.15.
5
Is CVE-2024-29135 exploitable by unauthenticated users?
Yes, CVE-2024-29135 is exploitable by unauthenticated users due to the unrestricted file upload feature.