CVE-2024-31210
Last modified
CVE-2024-31210 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. EPSS estimates a 0.95% chance of exploitation in the next 30 days.
Description
WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for installation (in order to move the file into place outside of the `uploads` directory) then the uploaded file remains temporary available in the Media Library despite it not being allowed. If the `DISALLOW_FILE_EDIT` constant is set to `true` on the site _and_ FTP credentials are required when uploading a new theme or plugin, then this technically allows an RCE when the user would otherwise have no means of executing arbitrary PHP code. This issue _only_ affects Administrator level users on single site installations, and Super Admin level users on Multisite installations where it's otherwise expected that the user does not have permission to upload or execute arbitrary PHP code. Lower level users are not affected. Sites where the `DISALLOW_FILE_MODS` constant is set to `true` are not affected. Sites where an administrative user either does not need to enter FTP credentials or they have access to the valid FTP credentials, are not affected. The issue was fixed in WordPress 6.4.3 on January 30, 2024 and backported to versions 6.3.3, 6.2.4, 6.1.5, 6.0.7, 5.9.9, 5.8.9, 5.7.11, 5.6.13, 5.5.14, 5.4.15, 5.3.17, 5.2.20, 5.1.18, 5.0.21, 4.9.25, 2.8.24, 4.7.28, 4.6.28, 4.5.31, 4.4.32, 4.3.33, 4.2.37, and 4.1.40. A workaround is available. If the `DISALLOW_FILE_MODS` constant is defined as `true` then it will not be possible for any user to upload a plugin and therefore this issue will not be exploitable.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wordpress | Wordpress | < 4.1.40 |
| Wordpress | Wordpress | >= 4.2, < 4.2.37 |
| Wordpress | Wordpress | >= 4.3, < 4.3.33 |
| Wordpress | Wordpress | >= 4.4, < 4.4.32 |
| Wordpress | Wordpress | >= 4.5, < 4.5.31 |
| Wordpress | Wordpress | >= 4.6, < 4.6.28 |
| Wordpress | Wordpress | >= 4.7, < 4.7.28 |
| Wordpress | Wordpress | >= 4.8, < 4.8.24 |
| Wordpress | Wordpress | >= 4.9, < 4.9.25 |
| Wordpress | Wordpress | >= 5.0, < 5.0.21 |
| Wordpress | Wordpress | >= 5.1, < 5.1.18 |
| Wordpress | Wordpress | >= 5.2, < 5.2.20 |
| Wordpress | Wordpress | >= 5.3, < 5.3.17 |
| Wordpress | Wordpress | >= 5.4, < 5.4.15 |
| Wordpress | Wordpress | >= 5.5, < 5.5.14 |
| Wordpress | Wordpress | >= 5.6, < 5.6.13 |
| Wordpress | Wordpress | >= 5.7, < 5.7.11 |
| Wordpress | Wordpress | >= 5.8, < 5.8.9 |
| Wordpress | Wordpress | >= 5.9, < 5.9.9 |
| Wordpress | Wordpress | >= 6.0, < 6.0.7 |
| Wordpress | Wordpress | >= 6.1, < 6.1.5 |
| Wordpress | Wordpress | >= 6.2, < 6.2.4 |
| Wordpress | Wordpress | >= 6.3, < 6.3.3 |
| Wordpress | Wordpress | >= 6.4.0, < 6.4.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-31210?
How severe is CVE-2024-31210?
How do I fix CVE-2024-31210?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-31205Saleor is an e-commerce platform. Starting in version 3.10.0…5.4
- CVE-2024-31206dectalk-tts is a Node package to interact with the aeiou Dec…8.2
- CVE-2024-31207Vite (French word for "quick", pronounced /vit/, like "veet"…5.9
- CVE-2024-31208Synapse is an open-source Matrix homeserver. A remote Matrix…6.5
- CVE-2024-31209oidcc is the OpenID Connect client library for Erlang. Denia…5.3
- CVE-2024-3121A remote code execution vulnerability exists in the create_c…3.3
- CVE-2024-31211WordPress is an open publishing platform for the Web. Unseri…9.8
- CVE-2024-31212InstantCMS is a free and open source content management syst…7.2
- CVE-2024-31213InstantCMS is a free and open source content management syst…5.4
- CVE-2024-31214Traccar is an open source GPS tracking system. Traccar versi…9.6
- CVE-2024-31215Mobile Security Framework (MobSF) is a security research pla…4.3
- CVE-2024-31216The source-controller is a Kubernetes operator, specialised …5.1
Are you affected by CVE-2024-31210?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
