Known CVE
WordPress Keydatas ≤ 2.5.2 - Arbitrary File Upload
The Keydatas plugin for WordPress (known in Chinese as "简数采集器") is vulnerable to unrestricted file uploads due to missing file-type validation in the keydatas_downloadImages function in all versions up to and including 2.5.2. An unauthenticated attacker can upload arbitrary files to the server — potentially leading to remote code execution, site takeover, or other severe compromise.
CVE-2024-6220
Critical2024CVSS 9.8CWE-434
cve2024 · wp · wp-plugin · wordpress · keydatas · file-upload · rce · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website