3D FlipBook Plugin Vulnerable to Arbitrary File Uploads
CVE-2024-9849
8.8HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 16 November 2024
What is CVE-2024-9849?
The Real 3D FlipBook WordPress Plugin lacks proper file type validation in its 'r3dfb_save_thumbnail_callback' function, allowing authenticated users with Author-level permissions or higher to upload arbitrary files. This vulnerability poses risks of potential remote code execution, compromising the server's security. All versions up to and including 4.6 are affected.
Affected Version(s)
Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder * <= 4.6