CVE-2024-6220

High PUBLISHED

简数采集器 (Keydatas) <= 2.5.2 - Unauthenticated Arbitrary File Upload

zhengdon · 简数采集器

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
9.8 Critical EPSS 35.7%

At a Glance

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

nuclei_scanner wordpress
CVE Published
Jul 17, 2024
Exploitation Reported
Jul 31, 2024
CVSS
9.8 Critical
EPSS
35.7%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
zhengdon
简数采集器

* to <= 2.5.2

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.