Overview
- Description
- The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload() function in all versions up to, and including, 1.6.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- Source
- security@wordfence.com
- NVD status
- Awaiting Analysis
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Weaknesses
- security@wordfence.com
- CWE-434
Social media
- Hype score
- Not currently trending
CVE-2024-10547 (CVSS:9.8, CRITICAL) is Awaiting Analysis. The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th..https://t.co/nlBQpUtNqa #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
14 Nov 2024
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2024-10547 (Published: 2024-11-09) - A critical vulnerability in e-plugins affects WP Membership versions. Users are urged to update to the latest version immediately to mitigate risks. For more details, visit: https://t.co/SpXR7FZ2Gf #CyberSecurity #VulnerabilityAlert
@transilienceai
13 Nov 2024
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2024-10547 (Published: 2024-11-09) - A critical vulnerability in e-plugins affects WP Membership (versions not specified). To protect your site, ensure you update to the latest version immediately. For more details, check the link: https://t.co/SpXR7FZ2Gf #CyberSecurity… h
@transilienceai
13 Nov 2024
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2024-10547 (Published: 2024-11-09) - Critical vulnerability in e-plugins for WP Membership (versions affected: all). Immediate remediation is crucial! Update to the latest version to secure your site. More info: https://t.co/SpXR7FZ2Gf #CyberSecurity #WordPress… https://t.
@transilienceai
13 Nov 2024
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2024-10547: CRITICAL] WordPress site admins beware! WP Membership plugin up to version 1.6.2 has a critical vulnerability allowing attackers to upload malicious files. Update now to stay secure.#cybersecurity,#vulnerability https://t.co/ijt5vJMzS9 https://t.co/tf7uZCG5nd
@CveFindCom
9 Nov 2024
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-10547 The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload() function in all … https://t.co/gdytAnnjn2
@CVEnew
9 Nov 2024
129 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes