Arbitrary File Uploads Vulnerability Affects Brizy Page Builder Plugin
CVE-2024-3242
8.8HIGH
What is CVE-2024-3242?
The Brizy Page Builder plugin for WordPress is susceptible to an arbitrary file upload vulnerability caused by inadequate file extension validation in the 'validateImageContent' function. This vulnerability affects all versions from inception up to and including version 2.4.43. Authenticated attackers with contributor or higher roles could leverage this flaw to upload potentially harmful files to the server, which could lead to remote code execution. The issue is mitigated in version 2.4.44, which prevents the upload of files with .sh and .php extensions, while version 2.4.45 includes a comprehensive fix for this vulnerability.
Affected Version(s)
Brizy – Page Builder * <= 2.4.44