← Back to browse · API

CVE-2024-12583

Severity
CRITICAL
CVSS
9.9
EPSS
0.01393
Risk score
40.09
CISA KEV
No
PoC
No
Published
2025-01-04
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2024-50974, GHSA-9RFW-73PX-X52V
Products
AlexaCRM:Dynamics 365 Integration 0 ≤1.3.23
Sources
euvd EUVD-2024-50974

Description

The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

References