CVE-2024-6828

HIGH EXPLOITED

Redux Framework <4.4.17 - XSS/Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-6828 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct stored cross-site scripting attacks and, in some rare cases, when the wp_filesystem fails to initialize - to Remote Code Execution.

Scores

CVSS v3 7.2
EPSS 0.0103
EPSS Percentile 59.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2024-07-22
CWE
CWE-434
Status published
Products (1)
davidanderson/Redux Framework 4.4.12 - 4.4.17
Published Jul 23, 2024
Tracked Since Feb 18, 2026