CVE-2024-52377: WordPress Instant Image Generator (One Click Image Uploads from Pixabay, Pexels and OpenAI) plugin <= 1.5.2 - Arbitrary File Upload vulnerability
Published Nov 14, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in bdthemes Instant Image Generator ai-image allows Upload a Web Shell to a Web Server.This issue affects Instant Image Generator: from n/a through <= 1.5.2.
Affected Software
1 affected component
BdThemes Instant Image Generator<=1.5.2
Event History
Nov 14, 2024
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-52377?
CVE-2024-52377 is rated as a critical vulnerability due to its potential to allow the upload of malicious web shells.
2
How do I fix CVE-2024-52377?
To fix CVE-2024-52377, update the Instant Image Generator plugin to version 1.5.5 or later.
3
Which versions of Instant Image Generator are affected by CVE-2024-52377?
CVE-2024-52377 affects BdThemes Instant Image Generator versions up to 1.5.4.
4
What impact does CVE-2024-52377 have on my website?
CVE-2024-52377 can lead to unauthorized file uploads, which may compromise the security of your web server.
5
Is CVE-2024-52377 exploitable without authentication?
Yes, CVE-2024-52377 can be exploited without authentication, making it particularly dangerous to public-facing websites.