plugin

Renee Work In Progress Vulnerabilities

4 known security issues reported for the Renee Work In Progress WordPress plugin. Most recent disclosed Oct 23, 2024.

2 high

Running Renee Work In Progress on your site? Check whether your installed version is affected.

Scan your site free

3D Work In Progress [renee-work-in-progress] <= 1.0.3 (unfixed + closed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in ReneeCussack 3D Work In Progress allows Upload a Web Shell to a Web Server.This issue affects 3D Work In Progress: from n/a through 1.0.3.

Affected:
up to 1.0.3
Fix:
No patched version reported
Disclosed:
Oct 23, 2024

CVE-2024-49652 on NVD →

3D Work In Progress [renee-work-in-progress] <= 1.0.3 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in ReneeCussack 3D Work In Progress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D Work In Progress: from n/a through 1.0.3.

Affected:
up to 1.0.3
Fix:
No patched version reported
Disclosed:
Oct 23, 2024

CVE-2024-49657 on NVD →

3D Work In Progress <= 1.0.3 - Authenticated (Subscriber+) Arbitrary File Upload

high

The 3D Work In Progress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which...

CVSS:
8.8
Affected:
up to 1.0.3
Fix:
No patched version reported
Disclosed:
Oct 21, 2024

CVE-2024-49652 on NVD →

3D Work In Progress <= 1.0.3 - Authenticated (Subscriber+) Arbitrary File Deletion

high

The 3D Work In Progress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 1.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easil...

CVSS:
8.8
Affected:
up to 1.0.3
Fix:
No patched version reported
Disclosed:
Oct 21, 2024

CVE-2024-49657 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database