Critical Vulnerabilities in WordPress (CVE-2024-10392, CVE-2024-8512)

Imechapishwa: Nov 04, 2024 09:42

Advisory No: TZCERT-SA-24-0036

Source: Wordfence

Software Affected: gpt3-ai-content-generator, w3speedster-wp

Overview

WordPress is vulnerable to critical vulnerabilities. Exploitation of these vulnerabilities may allow an unauthenticated attacker to execute code remotely.

Description

WordPress plugins gpt3-ai-content-generator, and w3speedster-wp are affected by the vulnerabilities tracked as CVE-2024-10392, and CVE-2024-8512 with CVSS scores of 9.8 and 9.1. The plugins are vulnerable due to missing file type validation in the 'handle_image_upload' function and the plugin passing user-supplied input to eval(). The vulnerabilities allow attackers to achieve remote code execution.

Impact

Successful exploitation of these vulnerabilities may allow the attackers to take control of the affected system.

Solution

WordPress has released security patches for these vulnerabilities. Users and administrators are encouraged to apply necessary updates.

Subscribe To TZ - CERT Newsletter

A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.

Subscribe
Ripoti Tukio