Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24253
HistoryMay 05, 2021 - 6:39 p.m.

CVE-2021-24253 Classyfrieds <= 3.8 - Authenticated Arbitrary File Upload to RCE

2021-05-0518:39:43
CWE-434
WPScan
www.cve.org

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.7%

The Classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds a listing, only checking the content-type in the request. This allows any authenticated user to upload arbitrary PHP files via the Add Listing feature of the plugin, leading to RCE.

CNA Affected

[
  {
    "product": "Classyfrieds",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThanOrEqual": "3.8",
        "status": "affected",
        "version": "3.8",
        "versionType": "custom"
      }
    ]
  }
]

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.7%

Related for CVELIST:CVE-2021-24253