ZeroHour

CVE-2024-6330

PoC
CVSS 3.1
9.8 critical
EPSS
2%p81
Published
()
Modified
Description

The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.

Vendors
geomywp
Products
geo my wordpress
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.