CVE-2024-9422
MEDIUM 6.6EPSS 0.8%
The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.
- CVSS v3.1
- 6.6 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H - EPSS
- 0.75% chance of exploitation in the next 30 days, 53th percentile
- Published
- 2024-11-22