Multiple critical vulnerabilities affecting WordPress (CVE-2024-3604, CVE-2024-6314, CVE-2024-6313, CVE-2024-6365)

Published On: Jul 11, 2024 05:25

Advisory No: TZCERT/SA/2024/07/10-2

Source: Wordfence

Software Affected: osm, iq-testimonials, forms-gutenberg, woo-product-tables

Overview

WordPress is vulnerable to four critical vulnerabilities. Exploitation of these vulnerabilities makes remote code execution possible

Description

Four WordPress plugins namely osm, iq-testimonials, forms-gutenberg, and woo-product-tables are affected by the vulnerabilities tracked as CVE-2024-3604, CVE-2024-6314, CVE-2024-6313, and CVE-2024-6365 respectively. Reasons for the flaws include insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query, insufficient file type validation in the 'process_image_upload' function, user’s ability to specify the allowed file types in the 'upload' function, and due to missing authorization and lack of sanitization of appended data in the languages/customTitle.php file. The attackers can exploit the vulnerabilities to execute arbitrary codes on the server.

Impact

Successful exploitation of these vulnerabilities may allow an attacker to take control of the affected system.

Solution

WordPress has released security patches for these vulnerabilities. Users and administrators are encouraged to apply necessary updates

Subscribe To TZ - CERT Newsletter

A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.

Subscribe
Report Incident