Unrestricted Upload of Dangerous File Vulnerability Affects Pie Register
CVE-2024-27957

10CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 March 2024

What is CVE-2024-27957?

The vulnerability identified allows unauthorized users to upload files of dangerous types to systems utilizing the Pie Register plugin. This could potentially lead to unauthorized access, data manipulation, or execution of malicious code, compromising the security and integrity of the affected websites. The issue impacts all versions of the Pie Register plugin from n/a to 3.8.3.1, making it essential for users to address this risk promptly by applying necessary security measures.

Affected Version(s)

Pie Register <= 3.8.3.1

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.