Cvefeed
Critical Remote Code Execution Vulnerabilities in WordPress Plugins Identified
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On June 8, 2026, three critical remote code execution vulnerabilities were disclosed affecting WordPress plugins. CVE-2024-58348 in the Background Image Cropper plugin allows unauthenticated file uploads via the ups.php endpoint, enabling arbitrary code execution. CVE-2023-54350 in the Augmented-Reality plugin also permits file uploads through the elFinder connector, while CVE-2023-54352 in the Seotheme plugin allows PHP code execution via uploaded files in the theme directory. All vulnerabilities have a high CVSS score, indicating severe risk. Currently, no patches are available for CVE-2024-58348, and the other two vulnerabilities are also unpatched. Administrators are advised to disable the affected plugins to mitigate risks. There are no known exploits in the wild at this time.
Key Points: • Three critical RCE vulnerabilities disclosed for WordPress plugins on June 8, 2026. • CVE-2024-58348 allows unauthenticated file uploads via ups.php in Background Image Cropper. • No patches available; disabling affected plugins is recommended for mitigation.