CVE Published: 22/11/2024 |
CVE Updated: 22/11/2024 |
CVE Year: 2024 Source: WPScan |
Vendor: Unknown |
Product: GEO my WP Status : PUBLISHED
CVE-2024-9422 Description
The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.