Arbitrary File Uploads Vulnerability Affects Brizy Page Builder Plugin
CVE-2024-1311
What is CVE-2024-1311?
The Brizy Page Builder plugin for WordPress is susceptible to an arbitrary file upload vulnerability stemming from inadequate validation of file types in the storeImages function. This flaw affects all versions up to and including 2.4.40. Authenticated attackers with contributor access or higher can exploit this vulnerability to upload arbitrary files to the server hosting the affected site. Such breaches can result in remote code execution, posing a significant risk to the integrity and security of the web application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Brizy β Page Builder 2.4.40
References
EPSS Score
9% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved