CVE-2024-0757: Insert or Embed Articulate Content into WordPress <= 4.3000000023 - Author+ Upload to RCE

5.4 CVSS

Description

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files

Classification

CVE ID: CVE-2024-0757

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.4

Problem Types

CWE-94 Improper Control of Generation of Code ('Code Injection')

Affected Products

Vendor: Unknown

Product: Insert or Embed Articulate Content into WordPress

Exploit Prediction Scoring System (EPSS)

EPSS Score: 32.0% (probability of being exploited)

EPSS Percentile: 96.51% (scored less or equal to compared to others)

EPSS Date: 2025-04-21 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-0757
https://wpscan.com/vulnerability/eccd017c-e442-46b6-b5e6-aec7bbd5f836/

Timeline