CVE-2024-5450: Bug Library Project Bug Library
Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.
The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an unauthenticated user to upload PHP files
Affected products
- Bug Library Project Bug Library: before 2.1.1 (fixed in 2.1.1)
Published 2024-07-13. Last modified 2026-06-17.