AI description
CVE-2024-11635 is a Remote Code Execution (RCE) vulnerability found in the WordPress File Upload plugin. It affects versions up to and including 4.24.12. The vulnerability allows unauthenticated attackers to execute remote code via the 'wfu_ABSPATH' cookie parameter.
- Description
- The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.
- Source
- security@wordfence.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@wordfence.com
- CWE-94
- Hype score
- Not currently trending
WordPress File Upload RCE (Part 2) : Full Disclosure of CVE-2024-11613 - When Patches Introduce New Vulnerabilities : https://t.co/YQAO4AvnHn Full Disclosure of CVE-2024-9939 & CVE-2024-11635 : https://t.co/NJV4TdNlur
@binitamshah
16 Mar 2025
3648 Impressions
9 Retweets
37 Likes
16 Bookmarks
0 Replies
0 Quotes
CVE-2024-11635 (CVSS:9.8, CRITICAL) is Awaiting Analysis. The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi..https://t.co/Vx0etBI81q #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
13 Jan 2025
23 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-11635 The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie param… https://t.co/HH2vXqrhO4
@CVEnew
8 Jan 2025
267 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A CVE of mine CVE-2024-11635 (CVSS:3.1 9.8 Critical) has been released today. You can read more about it at the link below https://t.co/sTo3fpY3vm I would be making a full disclosure exclusively on my blog https://t.co/Z46zGdurbe, on the 7th March 2025. Please save the date.
@theabrahack
7 Jan 2025
369 Impressions
0 Retweets
12 Likes
3 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:iptanus:wordpress_file_upload:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "0B5A82C7-FE3A-477E-AA13-EBC492A3C79F",
"versionEndExcluding": "4.24.15"
}
],
"operator": "OR"
}
]
}
]