Arbitrary File Uploads Vulnerability in Bit File Manager
CVE-2024-7770
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 10 September 2024
What is CVE-2024-7770?
The Bit File Manager, a widely used file management tool for WordPress, is subject to a vulnerability allowing authenticated attackers with Subscriber-level access and upload permissions to execute arbitrary file uploads. This occurs due to insufficient validation of file types in the upload function across all versions up to and including 6.5.5. Malicious users could potentially exploit this flaw to deliver harmful files to the server, raising concerns regarding remote code execution and overall website security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Bit File Manager β 100% Free & Open Source File Manager and Code Editor for WordPress * <= 6.5.5
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved