CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.6. It affects WordPress.
CVE
CVE-2024-9422
Severity
MEDIUM
CVSS
6.6
EPSS
0.73%
WordPress
Original NVD Description
The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.
Related CVEs
Other vulnerabilities affecting the same vendor(s)