CVE-2021-42362
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.
El plugin Popular Posts de WordPress es vulnerable a una carga de archivos arbitrarios debido a la insuficiente comprobación del tipo de archivo de entrada encontrada en el archivo ~/src/Image.php que hace posible que atacantes con acceso de nivel de colaborador y superior carguen archivos maliciosos que pueden ser usados para obtener una ejecución de código remota, en versiones hasta la 5.3.2 incluyéndola
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-07-14 First Exploit
- 2021-10-14 CVE Reserved
- 2021-11-12 CVE Published
- 2024-09-16 CVE Updated
- 2024-11-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
https://wpscan.com/vulnerability/bd4f157c-a3d7-4535-a587-0102ba4e3009 | Third Party Advisory | |
https://www.wordfence.com/vulnerability-advisories/#CVE-2021-42362 | Third Party Advisory |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordpress Popular Posts Project Search vendor "Wordpress Popular Posts Project" | Wordpress Popular Posts Search vendor "Wordpress Popular Posts Project" for product "Wordpress Popular Posts" | <= 5.3.2 Search vendor "Wordpress Popular Posts Project" for product "Wordpress Popular Posts" and version " <= 5.3.2" | wordpress |
Affected
|