Imechapishwa: Jul 04, 2024 17:04
Advisory No: TZCERT/SA/2024/07/04-1
Source: Wordfence
Software Affected: wp-nested-pages, addons-for-elementor and IMGspider
WordPress is vulnerable to four critical vulnerabilities. The attackers can leverage the vulnerabilities to take control of the affected system.
Three WordPress plugins namely wp-nested-pages, addons-for-elementor and IMGspider as affected by the vulnerabilities tracked as CVE-2024-5943, CVE-2024-2385, CVE-2024-6319, and CVE-2024-6318 respectively. Reasons for the flaws include missing or incorrect nonce validation on the 'settingsPage' function and missing santization of the 'tab' parameter, plugin's widgets through the 'style' attribute, and missing file type validation in the 'upload' and 'upload_img_file' functions in all versions up to, and including, 2.3.10. The attackers can exploit the vulnerabilities to execute remote arbitrary codes on affected system.
Successful exploitation of these vulnerabilities may allow an attacker to take control of affected system.
WordPress has released security patches for these vulnerabilities. Users and administrators are encouraged to apply necessary updates.
A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.