← Back to browse · API

CVE-2024-9307

Severity
CRITICAL
CVSS
9.9
EPSS
0.00971
Risk score
39.94
CISA KEV
No
PoC
No
Published
2024-11-06
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2024-49851, GHSA-PX29-MQ7H-P287
Products
themelooks:mFolio Lite 0 ≤1.2.1
Sources
euvd EUVD-2024-49851

Description

The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file or upload arbitrary EXE files on the affected site's server which may make remote code execution possible if the attacker can also gain access to run the .exe file, or trick a site visitor into downloading and running the .exe file.

References