CVE Database /
CVE-2024-3412
CVE · Critical
CVE-2024-3412 — WP STAGING – WordPress Backup, Restore, Migration & Clone [wp-staging] < 3.5.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-3412
|
WP STAGING – WordPress Backup, Restore, Migration & Clone [wp-staging] < 3.5.0 |
Unrestricted Upload of File with Dangerous Type |
Critical
9.1
|
< 3.5.0
|
3.5.0 |
2024-05-28 |
—
|
CVE-2024-3412
The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpstg_processing AJAX action in all versions up to, and including, 3.4.3. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Source:
CVE.org
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings