Arbitrary File Upload Vulnerability in School Management System for WordPress
CVE-2024-9659
9.8CRITICAL
What is CVE-2024-9659?
The School Management System for WordPress plugin is susceptible to an arbitrary file upload vulnerability due to inadequate file type validation within the mj_smgt_user_avatar_image_upload() function. This flaw is present in all versions up to and including 91.5.0, allowing unauthenticated users to potentially upload malicious files to the server of an affected site. This vulnerability could lead to remote code execution, facilitating various attack vectors that may compromise the integrity and security of the server.
Affected Version(s)
School Management System for Wordpress 0 <= 91.5.0