CVE-2024-6828
A security flaw exists in certain versions of the Redux Framework plugin for WordPress, allowing unauthorized users to upload arbitrary JSON files via a specific function. This vulnerability stems from inadequate checks on user permissions, enabling malicious actors to bypass authentication and exploit the issue. The potential consequences include cross-site scripting attacks and, under rare circumstances, remote code execution if the file system fails to initialize properly.
Based on public CVE data (MITRE/NVD).