CVE · High

CVE-2024-6828 — Redux Framework [redux-framework] < 4.4.18

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-6828 Redux Framework [redux-framework] < 4.4.18 Unrestricted Upload of File with Dangerous Type High 7.2 < 4.4.18 4.4.18 2024-07-22

CVE-2024-6828

A security flaw exists in certain versions of the Redux Framework plugin for WordPress, allowing unauthorized users to upload arbitrary JSON files via a specific function. This vulnerability stems from inadequate checks on user permissions, enabling malicious actors to bypass authentication and exploit the issue. The potential consequences include cross-site scripting attacks and, under rare circumstances, remote code execution if the file system fails to initialize properly.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.