Record summary

CVE-2024-6828 has a selected CVSS score of 7.2 (high).

Description

The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct stored cross-site scripting attacks and, in some rare cases, when the wp_filesystem fails to initialize - to Remote Code Execution.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 23, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List4.4.12 to ≤ 4.4.17affected

gutenberg_template_library_\&_redux_framework

Browse redux / gutenberg_template_library_\&_redux_framework

Default status: unknown

CVE List, VulnCheck4.4.12 to ≤ 4.4.17affected

References

8