Strategic Overview
- Status
- Patched in 1.16.2
- Affected Plugin
- WP Crontrol
- Affected Version
<= 1.16.1- CVSS
- 7.5High
- Weakness type
- CWE-494 · Download of Code Without Integrity Check
- CVE
CVE-2024-28850
At a glance
CVE-2024-28850 is a high-severity Download of Code Without Integrity Check vulnerability in the WP Crontrol WordPress plugin, affecting versions <= 1.16.1. It carries a CVSS score of 7.5 (reachable over the network; high confidentiality, integrity, availability impact). The issue is fixed in version 1.16.2; sites on affected versions should update now. Disclosed March 2024, reported by Calvin Alkan.
Vulnerability Overview
The WP Crontrol plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.1 when another vulnerability is present on the site that allows access to editing the database. This makes it possible for attackers to execute code on the server. Please see the advisory in references for more in depth details.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, and no interaction from a victim user. A successful exploit has high impact on confidentiality, integrity, availability — full site compromise territory.
CWE-494: Download of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
Remediation
Update to version 1.16.2, or a newer patched version
How does WordSec protect against this?
The fix is the thing that ends this: WP Crontrol 1.16.2 closes this, and updating the plugin is the step that ends it.
- Alerts
External References
Related records
Other vulnerabilities in WP Crontrol
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C