CVE-2024-9849: Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder <= 4.8 - Authenticated (Author+) Arbitrary File Upload
The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'r3dfbsavethumbnailcallback' function in all versions up to, and including, 4.8. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9849?
CVE-2024-9849 has a high severity due to its potential for arbitrary file uploads, which can lead to code execution on affected WordPress sites.
How do I fix CVE-2024-9849?
To fix CVE-2024-9849, update the 3D FlipBook Real 3D FlipBook WordPress Plugin to version 4.7 or higher.
What versions are affected by CVE-2024-9849?
CVE-2024-9849 affects all versions of the 3D FlipBook Real 3D FlipBook WordPress Plugin up to and including version 4.6.
What types of attacks can CVE-2024-9849 facilitate?
CVE-2024-9849 can facilitate attacks that exploit missing file type validation to upload malicious files to the server.
Who is the vendor of CVE-2024-9849?
The vendor of CVE-2024-9849 is 3D FlipBook, responsible for the Real 3D FlipBook WordPress Plugin.