CVE-2021-24161
Responsive Menu < 4.0.4 - CSRF to Arbitrary File Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.
En los plugins de WordPress Reponsive Menu (free y Pro) versiones anteriores a 4.0.4, unos atacantes podrían diseñar una petición y engañar a un administrador para que cargue un archivo zip que contenga archivos PHP maliciosos. El atacante podría entonces acceder a esos archivos para lograr una ejecución de código remota e infectar aún más el sitio objetivo
In the Responsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-02-10 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://wpscan.com/vulnerability/efca27e0-bdb6-4497-8330-081f909d6933 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.wordfence.com/blog/2021/02/multiple-vulnerabilities-patched-in-responsive-menu-plugin | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Expresstech Search vendor "Expresstech" | Responsive Menu Search vendor "Expresstech" for product "Responsive Menu" | < 4.0.4 Search vendor "Expresstech" for product "Responsive Menu" and version " < 4.0.4" | free, wordpress |
Affected
| ||||||
Expresstech Search vendor "Expresstech" | Responsive Menu Search vendor "Expresstech" for product "Responsive Menu" | < 4.0.4 Search vendor "Expresstech" for product "Responsive Menu" and version " < 4.0.4" | pro, wordpress |
Affected
|