CVE-2024-27972
WordPress WP Fusion Lite plugin <= 3.41.24 - Auth. Remote Code Execution (RCE) vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Very Good Plugins WP Fusion Lite allows Command Injection.This issue affects WP Fusion Lite: from n/a through 3.41.24.
Neutralización inadecuada de elementos especiales utilizados en una vulnerabilidad de comando ("Inyección de comando") en Very Good Plugins WP Fusion Lite permite la inyección de comando. Este problema afecta a WP Fusion Lite: desde n/a hasta 3.41.24.
The WP Fusion Lite – Marketing Automation and CRM Integration for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.41.24. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-02-28 CVE Reserved
- 2024-03-13 CVE Published
- 2024-04-04 EPSS Updated
- 2024-05-18 First Exploit
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
- CAPEC-248: Command Injection
References (2)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/wp-fusion-lite/wordpress-wp-fusion-lite-plugin-3-41-24-remote-code-execution-rce-vulnerability?_s_id=cve | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://github.com/truonghuuphuc/CVE-2024-27972-Poc | 2024-05-18 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wp Fusion Lite Search vendor "Wp Fusion Lite" | Wp Fusion Lite Search vendor "Wp Fusion Lite" for product "Wp Fusion Lite" | >= 0.0.0 <= 3.41.24 Search vendor "Wp Fusion Lite" for product "Wp Fusion Lite" and version " >= 0.0.0 <= 3.41.24" | en |
Affected
|