9.8
CVE-2024-6330
- EPSS 43.53%
- Veröffentlicht 19.08.2024 06:15:05
- Zuletzt bearbeitet 27.05.2025 21:06:37
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
GEO my WordPress <= 4.5.0.1 - Unauthenticated Local File Inclusion
The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.
Mögliche Gegenmaßnahme
GEO my WP: Update to version 4.5.0.2, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
GEO my WP
Version
*-4.5.0.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Geomywp ≫ Geo My Wordpress SwPlatformwordpress Version < 4.5.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 43.53% | 0.974 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|