Code Injection Vulnerability in MDTF Could Allow Attackers to Execute Malicious Code
CVE-2024-50450
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 28 October 2024
Badges
Summary
A code injection vulnerability exists in the WordPress Meta Data and Taxonomies Filter (MDTF) plugin due to improper control of code generation processes. This vulnerability can allow attackers to inject arbitrary code, potentially compromising the WordPress installation and leading to unauthorized access or loss of data. Affected versions include all prior to 1.3.3.4. Site administrators using these versions should take immediate action to update and mitigate risks associated with this vulnerability.
Affected Version(s)
WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved