Unknown File Upload Vulnerability in Revy Allows Web Shell Upload to Web Server
CVE-2024-54214
10CRITICAL
What is CVE-2024-54214?
The Roninwp Revy Plugin for WordPress presents a significant security risk due to an unrestricted upload of files with dangerous types. This vulnerability allows attackers to upload a malicious web shell to the server, compromising site security. The issue is prevalent in Revy versions from n/a up to 1.18. Website administrators using this plugin must act swiftly to mitigate potential threats by implementing the necessary updates and security measures.
Affected Version(s)
Revy <= 1.18