Arbitrary File Upload Vulnerability Affects Blox Page Builder Plugin
CVE-2024-6315
8.8HIGH
Summary
The Blox Page Builder plugin for WordPress is susceptible to arbitrary file uploads due to inadequate file type validation within the 'handleUploadFile' function. This vulnerability affects all versions up to and including 1.0.65. Authenticated users with contributor-level permissions and higher can exploit this flaw to upload arbitrary files to the server hosting the affected site. This unauthorized file upload could potentially facilitate remote code execution, posing a significant risk to the security of the WordPress installation and its associated data.
Affected Version(s)
Blox Page Builder * <= 1.0.65
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
István Márton