First published: Wed Oct 23 2024(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in Admin Verbalize WP Upload a Web Shell to a Web Server.This issue affects Verbalize WP: from n/a through 1.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Verbalize WP | <=1.0 | |
Verbalize WP | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-49668 is critical due to its potential to allow remote code execution through arbitrary file uploads.
To fix CVE-2024-49668, update the Verbalize WP plugin to the latest version or disable the plugin altogether until a secure patch is available.
CVE-2024-49668 affects Verbalize WP versions up to and including 1.0, specifically allowing unrestricted file uploads.
The impact of CVE-2024-49668 on your site can include unauthorized server access and potential malware deployment.
While there are no confirmed reports of active exploitation for CVE-2024-49668, the nature of the vulnerability suggests it is a target for attackers.