CVE-2024-13011: WP Foodbakery <= 4.7 - Unauthenticated Arbitrary File Upload

Critical (9.8)

Sign up for FREE to recieve instant alerts about this vulnerability!

Description

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Classification

CVE ID: CVE-2024-13011

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.8

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

Vendor: Chimpstudio

Product: WP Foodbakery

Timeline