CVE Database /
CVE-2024-3412
CVE · Critical
CVE-2024-3412 — WP STAGING – WordPress Backups, Restore, Migration & Clone [wp-staging] < 3.5.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-3412
|
WP STAGING – WordPress Backups, Restore, Migration & Clone [wp-staging] < 3.5.0 |
Unrestricted Upload of File with Dangerous Type |
Critical
9.1
|
< 3.5.0
|
3.5.0 |
2024-05-28 |
—
|
CVE-2024-3412
The WP STAGING plugin through version 3.4.3 contains a file upload vulnerability in the wpstg_processing AJAX action where file type validation is not performed. Attackers with administrator privileges or higher can exploit this to upload arbitrary files to the server, potentially enabling remote code execution. The issue affects all versions up to and including 3.4.3 and is resolved in version 3.5.0.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings