CVE-2024-6330

CVE-2024-6330: GEO my WordPress < 4.4.0.2 - Unauthenticated RCE via LFI

Vendor Unknown
Product GEO my WP
Published August 19, 2024
Last update August 19, 2024

CVSS base score

What the vulnerability does

01Description

The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.

Key dates

02Disclosure timeline

August 19, 2024 CVE published
August 19, 2024 Record updated