CVE-2024-38736: WordPress Realtyna Organic IDX plugin <= 4.14.13 - Arbitrary File Upload vulnerability
Published Jul 12, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Injection.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.13.
Affected Software
2 affected components
Realtyna Organic IDX plugin<=4.14.13
WordPress Realtyna Organic IDX plugin<=4.14.13
Event History
Jul 12, 2024
CVE Published
via MITRE·03:21 PM
Data Sourced
via MITRE·03:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38736?
CVE-2024-38736 is considered a high-severity vulnerability due to its potential for code injection through unrestricted file uploads.
2
How do I fix CVE-2024-38736?
To fix CVE-2024-38736, update the Realtyna Organic IDX plugin to the latest version beyond 4.14.13.
3
What systems are affected by CVE-2024-38736?
CVE-2024-38736 affects the Realtyna Organic IDX plugin versions up to and including 4.14.13.
4
What is the nature of CVE-2024-38736?
CVE-2024-38736 is an unrestricted file upload vulnerability that allows attackers to execute arbitrary code.
5
Can CVE-2024-38736 lead to data breaches?
Yes, CVE-2024-38736 can lead to data breaches by allowing unauthorized access to the server through code injection.