CVE-2024-5450: Bug Library Project Bug Library

Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.

The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an unauthenticated user to upload PHP files

Affected products

Published 2024-07-13. Last modified 2026-06-17.