CVE-2024-43160: WordPress BerqWP plugin <= 1.7.6 - Unauthenticated Arbitrary File Upload vulnerability
Published Aug 13, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.
Affected Software
2 affected components
BerqWP BerqWP<=1.7.6
WordPress BerqWP plugin<=1.7.6
Remediation
Information
Update to 1.7.7 or a higher version.
Event History
Aug 13, 2024
CVE Published
via MITRE·11:41 AM
Data Sourced
via MITRE·11:41 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43160?
CVE-2024-43160 is classified as a high severity vulnerability due to its potential for code injection.
2
How do I fix CVE-2024-43160?
To fix CVE-2024-43160, update BerqWP to version 1.7.7 or later.
3
What specific issue does CVE-2024-43160 address?
CVE-2024-43160 addresses an unrestricted upload of files with dangerous types, allowing for code injection.
4
Which versions of BerqWP are affected by CVE-2024-43160?
CVE-2024-43160 affects BerqWP versions up to and including 1.7.6.
5
Can CVE-2024-43160 be exploited remotely?
Yes, CVE-2024-43160 can be exploited remotely as it allows unauthenticated arbitrary file uploads.