logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-3022

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-3022

Description:
The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient filename validation in the 'bookingpress_process_upload' function in all versions up to, and including 1.0.87. This allows an authenticated attacker with administrator-level capabilities or higher to upload arbitrary files on the affected site's server, enabling remote code execution.
Last updated date:
03/13/2025
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/13/2025
Reference url to background

https://r0ot.notion.site/BookingPress-1-0-84-Authenticated-Administrator-Arbitrary-File-Upload-lead-to-RCE-e2603371c0c14d828144e26f2fdc1d01?pvs=4

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy