WordPress security by component
ConvertPlug
Plugin description
ConvertPlug is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published May 04, 2024; the highest published CVSS base score is 8.8.
Plugin slug:
convertplugLatest vulnerability
CVE-2024-3240: ConvertPlug: Code execution
ConvertPlug is affected by code execution. Exploitation requires an authenticated contributor account. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| May 04, 2024 |
CVE-2024-3240
ConvertPlug: Code execution
ConvertPlug is affected by code execution. Exploitation requires an authenticated contributor account. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.8
NVDPending
|
| May 04, 2024 |
CVE-2024-3237
ConvertPlug: A security weakness
ConvertPlug is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVDPending
|