CVE-2021-24962
WordPress File Upload < 4.16.3 - Contributor+ Path Traversal to RCE
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code execution.
Los plugins File Upload Free y Pro de WordPress versiones anteriores a 4.16.3, permiten a usuarios con un rol tan bajo como el de Contribuyente llevar a cabo un salto de ruta por medio de un argumento shortcode, que puede ser usado para subir un código PHP disfrazado de imagen dentro del directorio autocargado del plugin, resultando en una ejecución de código arbitrario
*Credits:
apple502j
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-01-14 CVE Reserved
- 2022-03-01 CVE Published
- 2023-11-17 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/7a95b3f2-285e-40e3-aead-41932c207623 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://plugins.trac.wordpress.org/changeset/2677722 | 2022-04-04 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Iptanus Search vendor "Iptanus" | Wordpress File Upload Search vendor "Iptanus" for product "Wordpress File Upload" | < 4.16.3 Search vendor "Iptanus" for product "Wordpress File Upload" and version " < 4.16.3" | wordpress |
Affected
| ||||||
Iptanus Search vendor "Iptanus" | Wordpress File Upload Pro Search vendor "Iptanus" for product "Wordpress File Upload Pro" | < 4.16.3 Search vendor "Iptanus" for product "Wordpress File Upload Pro" and version " < 4.16.3" | wordpress |
Affected
|