CVE-2024-33913: WordPress Xserver Migrator plugin <= 1.6.1 - CSRF to Arbitrary File Upload vulnerability
Published May 2, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability leading to Arbitrary File Upload in Xserver Migrator.This issue affects Xserver Migrator: from n/a through 1.6.1.
Affected Software
1 affected component
Xserver Xserver Migrator (WordPress plugin)<=1.6.1
Event History
May 2, 2024
CVE Published
via MITRE·10:59 AM
Data Sourced
via MITRE·10:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33913?
CVE-2024-33913 is classified as a high severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-33913?
To fix CVE-2024-33913, update the Xserver Migrator plugin to the latest version beyond 1.6.1.
3
What impact does CVE-2024-33913 have on my website?
CVE-2024-33913 can potentially allow an attacker to upload arbitrary files to your website, leading to possible remote code execution.
4
Which versions of Xserver Migrator are affected by CVE-2024-33913?
CVE-2024-33913 affects Xserver Migrator versions up to and including 1.6.1.
5
Is CVE-2024-33913 a known issue in the WordPress Xserver Migrator plugin?
Yes, CVE-2024-33913 is a known issue in the WordPress Xserver Migrator plugin affecting versions up to 1.6.1.