First published: Tue Aug 06 2024(Updated: )
The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'handle_uploaded_files' function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
CRM Perks CRM Perks Forms | <1.1.4 | |
CRM Perks | <=1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7484 is rated as a high severity vulnerability due to the potential for arbitrary file uploads.
To fix CVE-2024-7484, update the CRM Perks Forms plugin to version 1.1.4 or later.
Authenticated users with administrator-level capabilities on WordPress sites using versions of CRM Perks Forms up to 1.1.3 are affected by CVE-2024-7484.
CVE-2024-7484 is an arbitrary file upload vulnerability caused by insufficient file validation.
CVE-2024-7484 was reported and added to the NVD database, making users aware of the potential exploit.