CVE-2024-56278: WordPress WP Ultimate Exporter plugin <= 2.9.1 - Remote Code Execution (RCE) vulnerability
Published Jan 7, 2025
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders Inc., WP Ultimate Exporter wp-ultimate-exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through <= 2.9.1.
Affected Software
1 affected component
Smackcoders WP Ultimate Exporter<=2.9.1
Remediation
Information
Update the WordPress WP Ultimate Exporter wordpress plugin to the latest available version (at least 2.9.2).
Event History
Jan 7, 2025
CVE Published
via MITRE·10:49 AM
Data Sourced
via MITRE·10:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-56278?
The severity of CVE-2024-56278 is considered high due to its potential for PHP Remote File Inclusion.
2
How do I fix CVE-2024-56278?
To fix CVE-2024-56278, update Smackcoders WP Ultimate Exporter to version 2.9.2 or later.
3
What versions of WP Ultimate Exporter are affected by CVE-2024-56278?
CVE-2024-56278 affects all versions of WP Ultimate Exporter from n/a through 2.9.1.
4
What type of vulnerability is CVE-2024-56278?
CVE-2024-56278 is an improper control of generation of code vulnerability, commonly referred to as code injection.
5
Can CVE-2024-56278 lead to remote code execution?
Yes, CVE-2024-56278 can lead to remote code execution due to the PHP Remote File Inclusion aspect of the vulnerability.