Remote Code Execution and File Read Vulnerability in WordPress Plugin by Dynamics 365
CVE-2024-12583
What is CVE-2024-12583?
The Dynamics 365 Integration plugin for WordPress is compromised by a vulnerability that permits remote code execution and arbitrary file reading. This flaw, present in all versions up to and including 1.3.23, arises from inadequate input validation and sanitization within the render function that utilizes Twig templating. Authenticated attackers with Contributor-level access and above can potentially execute malicious code on the server, thereby compromising the integrity and security of the website.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Dynamics 365 Integration * <= 1.3.23
References
EPSS Score
9% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved