CVE-2024-32514: WordPress WP Poll Maker plugin <= 3.4 - Authenticated Arbitrary File Upload vulnerability
Published Apr 17, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.4.
Affected Software
3 affected components
InfoTheme WP Poll Maker<=3.4
WordPress WP Poll Maker<=3.4
InfoTheme Wp Poll Maker Wordpress<3.5
Event History
Apr 17, 2024
CVE Published
via MITRE·07:58 AM
Data Sourced
via MITRE·07:58 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32514?
CVE-2024-32514 is classified as a high severity vulnerability due to its potential for unrestricted file uploads.
2
How do I fix CVE-2024-32514?
To fix CVE-2024-32514, update the WP Poll Maker plugin to the latest version beyond 3.4.
3
What type of flaw is CVE-2024-32514?
CVE-2024-32514 is an unrestricted file upload vulnerability that allows attackers to upload malicious files.
4
Which versions of WP Poll Maker are affected by CVE-2024-32514?
CVE-2024-32514 affects all versions of WP Poll Maker from its initial release up to and including version 3.4.
5
What impact does CVE-2024-32514 have on my WordPress site?
CVE-2024-32514 can lead to remote code execution or server compromise if exploited by uploading malicious files.