WP REST API FNS Plugin [rest-api-fns] <= 1.0.0 (unfixed + closed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Vivek Tamrakar WP REST API FNS allows Upload a Web Shell to a Web Server.This issue affects WP REST API FNS: from n/a through 1.0.0.
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 20, 2024
CVE-2024-49329 on NVD →
WP REST API FNS Plugin [rest-api-fns] <= 1.0.0 (unfixed + closed)
unknown
[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in Vivek Tamrakar WP REST API FNS allows Authentication Bypass.This issue affects WP REST API FNS: from n/a through 1.0.0.
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 20, 2024
CVE-2024-49328 on NVD →
WP REST API FNS <= 1.0.0 - Unauthenticated Arbitrary File Upload
critical
The WP REST API FNS Plugin plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- CVSS:
- 9.8
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 17, 2024
CVE-2024-49329 on NVD →
WP REST API FNS <= 1.0.0 - Privilege Escalation
critical
The WP REST API FNS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to gain administrator privileges.
- CVSS:
- 9.8
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 17, 2024
CVE-2024-49328 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database