CVE-2024-2024
The Folders Pro plugin for WordPress is vulnerable to arbitrary

Publication date: 2024-06-14

Last updated on: 2024-11-21

Assigner: [email protected]

Description
The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_folders_file_upload' function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVSS Scores
EPSS Scores

Last evaluated: 2025-03-31

Probability:
Percentile:
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
This CVE does not appear in the KEV catalog.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
Meta Information
Date published:
2024-06-14
Date last modified:
2024-11-21
Date generated:
2025-04-08
NVD report: