# CVE-2024-7954

## Summary

- **CVE ID:** CVE-2024-7954
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-95, CWE-1286
- **Published:** Aug 23, 2024
- **Last Modified:** Mar 13, 2026

## Description

The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.

## Affected Products

- SPIP — SPIP (4.3.0-alpha)
- SPIP — SPIP (4.2.0)
- SPIP — SPIP (4.1.0)

## References

- [CNA](https://vulncheck.com/advisories/spip-porte-plume)
- [CNA](https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-3-0-alpha2-SPIP-4-2-13-SPIP-4.html)
- [CNA](https://thinkloveshare.com/hacking/spip_preauth_rce_2024_part_1_the_feather/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 90.05%
- **EPSS Percentile:** 99.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._