Code Injection Vulnerability in Cwicly Builder by Cwicly
CVE-2024-24707

9.9CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
3 April 2024

What is CVE-2024-24707?

The vulnerability in Cwicly Builder allows for unauthorized code injection, which can lead to remote code execution on websites using the affected product. This type of exposure enables malicious actors to manipulate server-side scripts, potentially compromising sensitive data and user integrity. Websites employing Cwicly Builder from an unspecified version up to 1.4.0.2 should implement security measures to mitigate these risks and ensure safe operations.

Affected Version(s)

Cwicly <= 1.4.0.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.