CVE-2024-9162
CVE-2024-9162: A critical WordPress vulnerability exists in the All-in-One WP Migration and Backup plugin. This arbitrary PHP Code Injection flaw allows attackers with administrator privileges to inject malicious PHP code into export files. Versions up to and including 7.86 are affected.
The vulnerability stems from missing file type validation, potentially leading to remote code execution. While the CVSS score is 0, the SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests a low to moderate risk. However, the presence of the "In The Wild" tag indicates active exploitation should be monitored. This CVE is significant because it can lead to complete website compromise if exploited, demanding immediate patching and security review. Users are strongly advised to update to the latest version of the plugin to mitigate this risk.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.