KEVIntel
9.8
CVSS
Critical

CVE-2024-6220

PUBLISHED

简数采集器 (Keydatas) <= 2.5.2 - Unauthenticated Arbitrary File Upload

Exploited in the wild Remote Low complexity No user interaction
Vendor
zhengdon
Product
简数采集器
Published
Jul 17, 2024
EPSS
5.0% · 89% pctl

Description

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

wordpress nuclei_scanner

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2024-07-31 09:34:09 UTC · Source

SSVC decision points

Exploitation
none
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
Wordfence Jul 31, 2024

Scanner integrations

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei