CVE-2024-3551
Last modified
CVE-2024-3551 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.0 via the 'data' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.0 via the 'data' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. This is limited to just PHP files.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-3551?
How severe is CVE-2024-3551?
How do I fix CVE-2024-3551?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-3549The Blog2Social: Social Media Auto Post & Scheduler plugin f…9.9
- CVE-2024-35492Cesanta Mongoose commit b316989 was discovered to contain a …7.5
- CVE-2024-35495An Information Disclosure vulnerability in the Telemetry com…4.3
- CVE-2024-35498A cross-site scripting (XSS) vulnerability in Grav v1.7.45 a…6.1
- CVE-2024-3550The WP Shortcodes Plugin — Shortcodes Ultimate plugin for Wo…5.4
- CVE-2024-35504A cross-site scripting (XSS) vulnerability in the login page…5.4
- CVE-2024-35510An arbitrary file upload vulnerability in /dede/file_manage_…9.8
- CVE-2024-35511phpgurukul Men Salon Management System v2.0 is vulnerable to…4.7
- CVE-2024-35512hmq v1.5.5 is vulnerable to Denial of Service (DoS) due to a…5.3
- CVE-2024-35515Insecure deserialization in sqlitedict up to v2.1.0 allows a…9.8
- CVE-2024-35517Netgear XR1000 v1.0.0.64 is vulnerable to command injection …7.2
- CVE-2024-35518Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection …6.8
Are you affected by CVE-2024-3551?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
