CVE-2024-10547

Published Nov 9, 2024

Last updated 5 days ago

Overview

Description
The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload() function in all versions up to, and including, 1.6.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Source
security@wordfence.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@wordfence.com
CWE-434

Social media

Hype score
Not currently trending
  1. CVE-2024-10547 (CVSS:9.8, CRITICAL) is Awaiting Analysis. The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th..https://t.co/nlBQpUtNqa #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    14 Nov 2024

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-2024-10547 (Published: 2024-11-09) - A critical vulnerability in e-plugins affects WP Membership versions. Users are urged to update to the latest version immediately to mitigate risks. For more details, visit: https://t.co/SpXR7FZ2Gf #CyberSecurity #VulnerabilityAlert

    @transilienceai

    13 Nov 2024

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CVE-2024-10547 (Published: 2024-11-09) - A critical vulnerability in e-plugins affects WP Membership (versions not specified). To protect your site, ensure you update to the latest version immediately. For more details, check the link: https://t.co/SpXR7FZ2Gf #CyberSecurity… h

    @transilienceai

    13 Nov 2024

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-2024-10547 (Published: 2024-11-09) - Critical vulnerability in e-plugins for WP Membership (versions affected: all). Immediate remediation is crucial! Update to the latest version to secure your site. More info: https://t.co/SpXR7FZ2Gf #CyberSecurity #WordPress… https://t.

    @transilienceai

    13 Nov 2024

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. [CVE-2024-10547: CRITICAL] WordPress site admins beware! WP Membership plugin up to version 1.6.2 has a critical vulnerability allowing attackers to upload malicious files. Update now to stay secure.#cybersecurity,#vulnerability https://t.co/ijt5vJMzS9 https://t.co/tf7uZCG5nd

    @CveFindCom

    9 Nov 2024

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2024-10547 The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload() function in all … https://t.co/gdytAnnjn2

    @CVEnew

    9 Nov 2024

    129 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes