Unrestricted Upload of File with Dangerous Type vulnerability in WP-Lister Lite for eBay
CVE-2024-32836

9.1CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 April 2024

What is CVE-2024-32836?

The WP-Lister Lite for eBay plugin by WP Lab has a security flaw that allows attackers to upload files of potentially dangerous types without proper restrictions. This vulnerability could lead to unauthorized access to the server, file compromise, and exploitation of other vulnerabilities. It pertains to all versions up to 3.5.11, and it is essential for users to review their current installations and apply necessary security measures to mitigate the risks associated with this flaw.

Affected Version(s)

WP-Lister Lite for eBay 0 <= 3.5.11

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.