Arbitrary File Upload Vulnerability Affects Blox Page Builder Plugin
CVE-2024-6315
8.8HIGH
What is CVE-2024-6315?
The Blox Page Builder plugin for WordPress is susceptible to arbitrary file uploads due to inadequate file type validation within the 'handleUploadFile' function. This vulnerability affects all versions up to and including 1.0.65. Authenticated users with contributor-level permissions and higher can exploit this flaw to upload arbitrary files to the server hosting the affected site. This unauthorized file upload could potentially facilitate remote code execution, posing a significant risk to the security of the WordPress installation and its associated data.
Affected Version(s)
Blox Page Builder * <= 1.0.65