CVE-2024-37228: WordPress InstaWP Connect plugin <= 0.1.0.38 - Arbitrary File Upload vulnerability
Published Jun 24, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.38.
Affected Software
3 affected components
InstaWP Instawp Connect Wordpress<0.1.0.39
InstaWP Team InstaWP Connect<=0.1.0.38
WordPress InstaWP Connect<=0.1.0.38
Remediation
Information
Update to 0.1.0.39 or a higher version.
Event History
Jun 24, 2024
CVE Published
via MITRE·12:35 PM
Data Sourced
via MITRE·12:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37228?
CVE-2024-37228 is classified as a Code Injection vulnerability which can lead to unauthorized code execution.
2
How do I fix CVE-2024-37228?
To fix CVE-2024-37228, upgrade InstaWP Connect to version 0.1.0.39 or later.
3
Who is affected by CVE-2024-37228?
CVE-2024-37228 affects users of InstaWP Connect versions up to 0.1.0.38.
4
What is the nature of the vulnerability in CVE-2024-37228?
CVE-2024-37228 involves improper control of code generation, allowing for potential code injection.
5
What are the potential consequences of CVE-2024-37228?
Exploitation of CVE-2024-37228 can lead to unauthorized code execution on affected systems.