← Back to browse · API

CVE-2024-11082

Severity
CRITICAL
CVSS
9.9
EPSS
0.01163
Risk score
40.01
CISA KEV
No
PoC
No
Published
2024-11-28
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2024-34059, GHSA-R5GW-2HVF-HR4W
Products
Tumult Inc:Tumult Hype Animations 0 ≤1.9.15
Sources
euvd EUVD-2024-34059

Description

The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hypeanimations_panel() function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

References