Back to Labs
Security Advisory

CVE-2024-50473

About

Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through <= 3.1.3.

Weakness (CWE):CWE-434

Rainforest analyst review

The Ajar in5 Embed plugin allows an unrestricted file upload, and the intended endgame is spelled out plainly: upload a web shell to the server. There's no authentication in the way, so a single crafted upload can drop executable code, and from that shell the attacker owns the site — content, database, and a foothold into whatever hosts it.

This is the combination that draws automated exploitation fastest: unauthenticated, a perfect 10.0, and a widely distributable WordPress plugin. Mass-scanning botnets hunt precisely for unauthenticated upload-to-shell bugs because the path is generic and the reward is complete control, so reachable installs tend to see indiscriminate probing soon after disclosure.

The real difficulty is the WordPress inventory gap — these plugins are installed per-site and rarely tracked centrally. So our work is turning the scary headline into a short list: across everything we host, which sites carry Ajar in5 Embed, at what version, and is the vulnerable upload path internet-reachable. Where we can't patch instantly, blocking the upload endpoint at the edge buys time, but the fix is getting every affected site past the vulnerable version.

References

Related CVEs

Frequently asked questions

What is CVE-2024-50473?

Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through <= 3.1.3.

How severe is CVE-2024-50473?

CVE-2024-50473 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.

How is CVE-2024-50473 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

How do I fix CVE-2024-50473?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email