CVE-2024-3277
CVSS 3.1 Score 5.0 of 10 (medium)
Details
Published May 30, 2024
Summary
CVE-2024-3277 is a vulnerability affecting the Yumpu ePaper publishing plugin for WordPress. This issue stems from a missing capability check on the ajax_handler function, which exists in all versions up to and including 2.0.24. Consequently, authenticated attackers with subscriber-level access and above can exploit this flaw to upload PDF files and publish them unauthorized, in addition to modifying the API key. This vulnerability poses a significant risk to WordPress sites using the Yumpu plugin and necessitates an immediate update to a patched version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share