CVE-2024-0844 describes a Local File Inclusion vulnerability in version 2.1.6 of the Popup More Popups, Lightboxes, and more popup modules plugin for WordPress, specifically affecting the felixmoira ai_popup product. This flaw allows authenticated attackers with administrator privileges to include and execute arbitrary PHP files ending in "Form.php" on the server. Rated 7.2 HIGH on the CVSS scale, this vulnerability carries significant risk due to its potential for bypassing access controls, exfiltrating sensitive data, and achieving remote code execution. The attack requires high privileges but has low attack complexity, posing a severe threat once an administrator account is compromised. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.5CPE matchmatch criteria | cpe:2.3:a:felixmoira:ai_popup:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.