References https://nvd.nist.gov/vuln/detail/CVE-2024-2073 https://cve.imfht.com/detail/CVE-2024-2073 https://vuldb.com/?id.255388 https://vuldb.com/ar/vuln/255388 https://access.redhat.com/security/cve/cve-2024-2073 https://github.com/advisories/GHSA-9mcq-4mx8-6h4w https://scm.cms.hu-berlin.de/safeguarding/cvelistV5/-/blob/275062f160a5e64bd1e1c7d405f34dde60f5a4f4/cves/2024/2xxx/CVE-2024-2073.json https://www.incibe.es/incibe-cert/alerta-temprana/vulnerabilidades/cve-2024-2073 https://www.cisa.gov/news-events/bulletins/sb24-064 https://github.com/vanitashtml/CVE-Dumps/blob/main/Block%20Inserter%20for%20Dynamic%20Content%20-%20Sql%20Injection.md https://cve.yack.one/cve/CVE-2024-2073 https://cve.imfht.com/detail/CVE-2024-2073
Related VulnerabilitiesPoCCVE-2026-60105: Monsta FTP <= 2.14.4 - Unauthenticated SSRF via IPv6 Blocklist BypassPoCCVE-2026-0743: WP Content Permission <= 1.2 - Cross-Site ScriptingPoCCVE-2026-5032: W3 Total Cache <= 2.9.3 - Unauthenticated Dynamic Security Token DisclosurePoCmixed-active-content: Mixed Active ContentMasterStudy LMS /wp-admin/admin-ajax.php?action=stm_lms_load_content 文件包含漏洞(CVE-2024-3136)WordPress LearnPress /wp-json/lp/v1/load_content_via_ajax 信息泄露漏洞(CVE-2025-11368)WordPress Frontend Login and Registration Blocks /wp-admin/admin-ajax.php 权限绕过漏洞(CVE-2025-3605)广联达OA /GTP/IM/Services/Group/Broadcast/MsgBroadcastContent.aspx SQL 注入漏洞PoCCVE-2026-47670: DbGate - Remote Code Execution via Dynamic Import BypassWordPress Easy Appointments插件 /eablocks/ea_appointments/ 信息泄露漏洞(CVE-2026-2262)PoCCVE-2025-1361: IP2Location Country Blocker < 2.38.9 - Unauthenticated Information DisclosureWordPress Plugin Mayosis Core /wp-content/plugins/mayosis-core/library/wave-audio/peaks/remote_dl.php 文件读取漏洞 (CVE-2025-1565)秒优科技-供应链管理系统 /Content/page/attachmentImg.aspx 信息泄露漏洞