VYPR
Unrated severityNVD Advisory· Published Nov 22, 2024· Updated Nov 22, 2024

GEO My WordPress < 4.5 - Admin+ Arbitrary File Upload

CVE-2024-9422

Description

The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.