CVE-2024-12300 — The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing capability check on the set_ar_featured_image() function in all versions up to, an — CVE Database · The Intelligence Room