Unauthenticated JSON File Uploads Vulnerability Affects Redux Framework Plugin
CVE-2024-6828

7.2HIGH

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
23 July 2024

What is CVE-2024-6828?

The Redux Framework plugin for WordPress contains a vulnerability that allows unauthenticated users to upload JSON files due to inadequate authorization checks within the Redux_Color_Scheme_Import function. This security loophole empowers malicious actors to perform stored cross-site scripting (XSS) attacks, which can be particularly damaging in the context of website integrity and user data. In rare scenarios, if the wp_filesystem initialization process fails, it could even lead to remote code execution (RCE), thereby posing severe risks to affected WordPress installations.

Affected Version(s)

Redux Framework 4.4.12 <= 4.4.17

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Villu Orav
.