← Back to CVE List

CVE-2024-6828

Published: 2024-07-23T02:15Z
Last Modified: 2024-11-21T09:50Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct stored cross-site scripting attacks and, in some rare cases, when the wp_filesystem fails to initialize - to Remote Code Execution. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt