ZeroHour

CVE-2021-24253

PoC ×2
CVSS 3.1
8.8 high
EPSS
2%p79
Published
()
Modified
Description

The Classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds a listing, only checking the content-type in the request. This allows any authenticated user to upload arbitrary PHP files via the Add Listing feature of the plugin, leading to RCE.

Vendors
classyfrieds project
Products
classyfrieds
Ecosystems
WordPress
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.