← Back to browse · API

CVE-2024-6330

Severity
CRITICAL
CVSS
9.8
EPSS
0.02143
Risk score
39.95
CISA KEV
No
PoC
No
Published
2024-08-19
Modified
2024-08-19
First seen
2026-08-07
Aliases
EUVD-2024-47444, GHSA-XV4G-G9FH-FQRJ
Products
Unknown:GEO my WP 0 <4.5.0.2
Sources
euvd EUVD-2024-47444

Description

The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.

References