CVE-2024-5080: WP eMember < 10.6.6 - Admin+ Arbitrary File Upload
Published Jul 13, 2024
·Updated
The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on the server
Affected Software
2 affected components
Tipsandtricks-hq Wp Emember Wordpress<10.6.6
WordPress wp-eMember<10.6.6
Event History
Jul 13, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5080?
CVE-2024-5080 has a high severity rating due to its ability to allow arbitrary file uploads.
2
How do I fix CVE-2024-5080?
To fix CVE-2024-5080, update the wp-eMember WordPress plugin to version 10.6.6 or later.
3
What types of files can be uploaded due to CVE-2024-5080?
CVE-2024-5080 allows the upload of arbitrary files, including potentially harmful PHP files.
4
Who is affected by CVE-2024-5080?
CVE-2024-5080 affects users of the wp-eMember WordPress plugin prior to version 10.6.6.
5
What are the potential consequences of CVE-2024-5080?
The consequences of CVE-2024-5080 include the possibility of remote code execution and server compromise.