CVE-2024-5630

HIGH

WordPress Plugin <4.3 - RCE

Title source: llm
STIX 2.1

Description

The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/538c875f-4c20-4be0-8098-5bddb7aecff4/

Scores

CVSS v3 8.8
EPSS 0.0113
EPSS Percentile 78.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
elearningfreak/insert_or_embed_articulate_content < 4.3000000024
Published Jul 15, 2024
Tracked Since Feb 18, 2026