CVE-2024-9849
CVE-2024-9849 is a critical WordPress plugin vulnerability in the 3D FlipBook plugin, allowing arbitrary file uploads. This flaw exists because of missing file type validation within the 'r3dfb_save_thumbnail_callback' function, affecting versions up to 4.6. Authenticated attackers with Author-level or higher access can exploit this to upload malicious files to the server. While the CVSS score is 0, indicating no immediate exploit, the SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests a moderate risk, especially considering the presence of CWE-434 (Unrestricted Upload of File with Dangerous Type). Successful exploitation could lead to remote code execution. The 'In The Wild' tag shows that threat actors are actively looking for this vulnerability. Mitigation is recommended to reduce the attack surface.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.