CVE-2024-6828
HIGH EXPLOITEDRedux Framework <4.4.17 - XSS/Code Injection
Title source: llmExploitation Summary
CVE-2024-6828 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct stored cross-site scripting attacks and, in some rare cases, when the wp_filesystem fails to initialize - to Remote Code Execution.
References (7)
Core 7
Core References
Scores
CVSS v3
7.2
EPSS
0.0103
EPSS Percentile
59.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
VulnCheck KEV
2024-07-22
CWE
CWE-434
Status
published
Products (1)
davidanderson/Redux Framework
4.4.12 - 4.4.17
Published
Jul 23, 2024
Tracked Since
Feb 18, 2026