Lucene search

K
cvelistWordfenceCVELIST:CVE-2021-42362
HistoryNov 12, 2021 - 12:00 a.m.

CVE-2021-42362 WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload

2021-11-1200:00:00
CWE-434
Wordfence
www.cve.org
1

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

9.1 High

AI Score

Confidence

High

0.955 High

EPSS

Percentile

99.4%

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "WordPress Popular Posts",
    "vendor": "WordPress Popular Posts",
    "versions": [
      {
        "lessThanOrEqual": "5.3.2",
        "status": "affected",
        "version": "0.0",
        "versionType": "custom"
      }
    ]
  }
]

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

9.1 High

AI Score

Confidence

High

0.955 High

EPSS

Percentile

99.4%