CVE-2024-52403: WordPress User Management plugin <= 1.1 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in Saad Iqbal User Management user-management allows Upload a Web Shell to a Web Server.This issue affects User Management: from n/a through <= 1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52403?
CVE-2024-52403 is rated as a high-severity vulnerability due to its potential for allowing arbitrary file uploads, leading to severe security risks.
How do I fix CVE-2024-52403?
To fix CVE-2024-52403, update the WPExperts User Management plugin to the latest version beyond 1.1 that addresses this vulnerability.
Who is affected by CVE-2024-52403?
CVE-2024-52403 affects users of the WPExperts User Management plugin version 1.1 and earlier.
What type of files can be uploaded due to CVE-2024-52403?
CVE-2024-52403 allows the upload of files with dangerous types, which can include malicious web shells.
Is there a proof of concept for CVE-2024-52403?
A proof of concept (PoC) for CVE-2024-52403 may be available in security forums or advisories, illustrating how this vulnerability can be exploited.