CVE-2024-56278
WordPress WP Ultimate Exporter plugin <= 2.9.1 - Remote Code Execution (RCE) vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders WP Ultimate Exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through 2.9.1.
La vulnerabilidad de control inadecuado de generación de código ('inyección de código') en WP Ultimate Exporter de Smackcoders permite la inclusión remota de archivos PHP. Este problema afecta a WP Ultimate Exporter: desde n/a hasta 2.9.1.
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-12-18 CVE Reserved
- 2025-01-03 CVE Published
- 2025-01-08 CVE Updated
- 2025-01-08 EPSS Updated
- 2025-01-08 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
- CAPEC-193: PHP Remote File Inclusion
References (2)
URL | Date | SRC |
---|---|---|
https://github.com/DoTTak/CVE-2024-56278 | 2025-01-08 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wp Ultimate Exporter Search vendor "Wp Ultimate Exporter" | Wp Ultimate Exporter Search vendor "Wp Ultimate Exporter" for product "Wp Ultimate Exporter" | >= 0.0.0 <= 2.9.1 Search vendor "Wp Ultimate Exporter" for product "Wp Ultimate Exporter" and version " >= 0.0.0 <= 2.9.1" | en |
Affected
|