Arbitrary File Uploads Vulnerability Affects Brizy Page Builder Plugin
CVE-2024-1311
8.8HIGH
Summary
The Brizy Page Builder plugin for WordPress is susceptible to an arbitrary file upload vulnerability stemming from inadequate validation of file types in the storeImages function. This flaw affects all versions up to and including 2.4.40. Authenticated attackers with contributor access or higher can exploit this vulnerability to upload arbitrary files to the server hosting the affected site. Such breaches can result in remote code execution, posing a significant risk to the integrity and security of the web application.
Affected Version(s)
Brizy – Page Builder 2.4.40
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Matthew Rollings