peter bassill · operator
$ cve CVE-2024-10124 JSON

CVE-2024-10124

9.8
CRITICAL · CVSS 3.1 · EPSS 32.7% (pctl 98)

Patch early

EPSS 32.7% — above the 10% action threshold.

Description

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the tp_install() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. This vulnerability was partially patched in version 1.1.1.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS32.73% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-284
On CISA KEVno
Public exploitnone known
Published2024-12-12
Last modified2026-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD