Security Advisory

CVE-2024-6228

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-06 06:00:01
Last updated 2026-07-06 12:09:45
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to build a server-side file inclusion path, allowing authenticated users with subscriber-level access and above to include and execute arbitrary local PHP files on the server.