ZeroHour

CVE-2021-24311

PoC ×2
CVSS 3.1
8.8 high
EPSS
2%p77
Published
()
Modified
Description

The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any authenticated users.

Vendors
external media project
Products
external media
Ecosystems
WordPress
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.