
🚨 CVE-2024-11613: WordPress File Upload <= 4.24.15... Unauthenticated RCE through unsanitized 'source' param in wfu_file_downloader.php - 9.8 CVSS means instant shells on 10... https://zerodaysignal.com/vulnerability/CVE-2024-11613 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The tweet announces a critical RCE flaw in WordPress File Upload plugin (<=4.24.15) with a CVSS of 9.8, linking to a detailed write‑up, but it does not mention exploitation, patching, or PoC code.
