CVE-2024-1165
CVE-2024-1165 allows directory traversal in the Brizy WordPress plugin. This vulnerability enables authenticated attackers to upload files to any location on the server. The Brizy Page Builder plugin, up to version 2.4.39, is affected by this directory traversal flaw. With contributor-level access or higher, attackers can exploit the 'id' parameter. This can lead to arbitrary file upload and potential compromise of the WordPress site. While the CVSS score is 6.5, indicating a medium severity, the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting a lower immediate risk compared to critical vulnerabilities. However, because it is tagged In The Wild, monitoring for exploits is still critical. This vulnerability is significant because it allows attackers with relatively low privileges to gain significant control over the server's file system, potentially leading to code execution or data breaches.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.