CVE-2024-51919: WordPress Fancy Product Designer plugin <= 6.4.3 - Unauthenticated Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Fancy Product Designer. This issue affects Fancy Product Designer: from n/a through 6.4.3.
Other sources
Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer: from n/a through <= 6.4.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51919?
CVE-2024-51919 has a high severity due to the potential for unrestricted file uploads leading to arbitrary code execution.
How do I fix CVE-2024-51919?
To fix CVE-2024-51919, update the Fancy Product Designer plugin to version 6.4.4 or newer.
What software is affected by CVE-2024-51919?
CVE-2024-51919 affects Fancy Product Designer versions up to and including 6.4.3 and the WordPress Fancy Product Designer plugin versions up to and including 6.4.3.
Can CVE-2024-51919 be exploited remotely?
Yes, CVE-2024-51919 can be exploited remotely without authentication, allowing attackers to upload malicious files.
What types of files are considered dangerous in the context of CVE-2024-51919?
In the context of CVE-2024-51919, dangerous file types include executable scripts and files with extensions that can execute code on the server.