CVE-2024-9422

CVE-2024-9422: GEO My WordPress < 4.5 - Admin+ Arbitrary File Upload

Vendor Unknown
Product GEO my WP
Published November 22, 2024
Last update November 22, 2024

CVSS base score

What the vulnerability does

01Description

The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

Key dates

02Disclosure timeline

November 22, 2024 CVE published
November 22, 2024 Record updated