CVE-2024-11270: Webinarpress
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function and missing file type validation in all versions up to, and including, 1.33.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary files that can lead to remote code execution.
Affected products
- Webinarpress Webinarpress: before 1.33.25 (fixed in 1.33.25)
Published 2025-01-08. Last modified 2026-06-17.