Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24890
HistorySep 26, 2022 - 12:35 p.m.

CVE-2021-24890 Scripts Organizer < 3.0 - Unauthenticated Arbitrary File Upload

2022-09-2612:35:29
CWE-862
CWE-352
WPScan
www.cve.org
4
wordpress plugin
unauthenticated
arbitrary file upload
csrf checks

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

40.8%

The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any way, which could allow unauthenticated users to put arbitrary PHP code in a file

CNA Affected

[
  {
    "product": "scripts-organizer",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "3.0",
        "status": "affected",
        "version": "3.0",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

40.8%

Related for CVELIST:CVE-2021-24890