CVE-2021-24499
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
7Exploited in Wild
-Decision
Descriptions
The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.
El tema Workreap WordPress versiones anteriores a 2.2.2, las acciones AJAX workreap_award_temp_file_uploader y workreap_temp_file_uploader, no llevaban a cabo comprobaciones de nonce, ni comprueban que la petición proviene de un usuario válido de ninguna otra forma. Los endpoints permitían subir archivos arbitrarios al directorio uploads/workreap-temp. Los archivos subidos no se saneaban ni se comprobaban, permitiendo a un visitante no autenticado subir código ejecutable como scripts php
WordPress theme Workreap version 2.2.2 suffers from a remote shell upload vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-07-02 CVE Published
- 2021-09-20 First Exploit
- 2024-08-03 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/172876/WordPress-Workreap-2.2.2-Shell-Upload.html |
|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/172876 | 2023-06-12 | |
https://www.exploit-db.com/exploits/51510 | 2023-06-09 | |
https://github.com/j4k0m/CVE-2021-24499 | 2021-09-20 | |
https://github.com/jytmX/CVE-2021-24499 | 2023-09-29 | |
https://github.com/hh-hunter/cve-2021-24499 | 2021-10-06 | |
https://jetpack.com/2021/07/07/multiple-vulnerabilities-in-workreap-theme | 2024-08-03 | |
https://wpscan.com/vulnerability/74611d5f-afba-42ae-bc19-777cdf2808cb | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Amentotech Search vendor "Amentotech" | Workreap Search vendor "Amentotech" for product "Workreap" | < 2.2.2 Search vendor "Amentotech" for product "Workreap" and version " < 2.2.2" | wordpress |
Affected
|