The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/81320923-767c-43f0-a8eb-b398c306c16f/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
09 Jun 2025, 16:50
Type | Values Removed | Values Added |
---|---|---|
First Time |
Geomywp geo My Wordpress Premium Settings
|
|
CPE | cpe:2.3:a:geomywp:geo_my_wordpress_premium_settings:*:*:*:*:*:wordpress:*:* |
15 May 2025, 15:53
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-22 06:15
Updated : 2025-06-09 16:50
NVD link : CVE-2024-9422
Mitre link : CVE-2024-9422
JSON object : View
Products Affected
geomywp
- geo_my_wordpress_premium_settings
- geo_my_wordpress
CWE