CVE-2024-6823

The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX action in all versions up to, and including, 3.18. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Configurations

Configuration 1 (hide)

cpe:2.3:a:davidlingren:media_library_assistant:*:*:*:*:*:wordpress:*:*

History

07 Feb 2025, 19:13

Type Values Removed Values Added
CPE cpe:2.3:a:davidlingren:media_library_assistant:*:*:*:*:*:wordpress:*:*
Summary
  • (es) El complemento Media Library Assistant para WordPress es vulnerable a cargas de archivos arbitrarias debido a la falta de validación del tipo de archivo que involucra la acción AJAX mla-inline-edit-upload-scripts en todas las versiones hasta la 3.18 incluida. Esto hace posible que atacantes autenticados, con acceso de nivel de autor y superior, carguen archivos arbitrarios en el servidor del sitio afectado, lo que puede hacer posible la ejecución remota de código.
First Time Davidlingren
Davidlingren media Library Assistant
References () https://plugins.trac.wordpress.org/browser/media-library-assistant/trunk/includes/class-mla-settings.php#L32 - () https://plugins.trac.wordpress.org/browser/media-library-assistant/trunk/includes/class-mla-settings.php#L32 - Product
References () https://plugins.trac.wordpress.org/changeset/3133909/ - () https://plugins.trac.wordpress.org/changeset/3133909/ - Patch
References () https://wordpress.org/plugins/media-library-assistant/#developers - () https://wordpress.org/plugins/media-library-assistant/#developers - Release Notes
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/9a446fe7-c97a-436e-b494-b924e6518297?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/9a446fe7-c97a-436e-b494-b924e6518297?source=cve - Third Party Advisory

13 Aug 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-13 06:15

Updated : 2025-02-07 19:13


NVD link : CVE-2024-6823

Mitre link : CVE-2024-6823

CVE.ORG link : CVE-2024-6823


JSON object : View

Products Affected

davidlingren

  • media_library_assistant
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type