1 results (0.008 seconds)
CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 0
CVE-2024-10578 – Pubnews <= 1.0.7 - Unauthenticated Arbitrary Plugin Installation
https://notcve.org/view.php?id=CVE-2024-10578
05 Dec 2024 — The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pubnews_importer_plugin_action_for_notice() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins that can be leveraged to exploit other vulnerabilities. • https://themes.trac.wordpress.org/browser/pubnews/1.0.7/inc/admin/admin.php#L1017 • CWE-434: Unrestricted Upload of File with Dangerous Type •