CVE-2024-12583 – Dynamics 365 Integration Plugin for WordPress Remote Code Execution and Arbitrary File Read Vulnerability

CVE ID : CVE-2024-12583

Published : Jan. 4, 2025, 9:15 a.m. | 1 hour, 1 minute ago

Description : The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

Severity: 9.9 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE-2024-12583 – Dynamics 365 Integration Plugin for WordPress Remote Code Execution and Arbitrary File Read Vulnerability