Remote Code Execution and File Read Vulnerability in WordPress Plugin by Dynamics 365
CVE-2024-12583
9.9CRITICAL
What is CVE-2024-12583?
The Dynamics 365 Integration plugin for WordPress is compromised by a vulnerability that permits remote code execution and arbitrary file reading. This flaw, present in all versions up to and including 1.3.23, arises from inadequate input validation and sanitization within the render function that utilizes Twig templating. Authenticated attackers with Contributor-level access and above can potentially execute malicious code on the server, thereby compromising the integrity and security of the website.
Affected Version(s)
Dynamics 365 Integration * <= 1.3.23