CVE-2024-11635 – Acunil WordPress File Upload Remote Code Execution Vulnerability

CVE ID : CVE-2024-11635

Published : Jan. 8, 2025, 8:15 a.m. | 1 hour ago

Description : The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the ‘wfu_ABSPATH’ cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE-2024-11635 – Acunil WordPress File Upload Remote Code Execution Vulnerability