ZeroHour

CVE-2021-24370

PoC ×5
CVSS 3.1
9.8 critical
EPSS
47%p99
Published
()
Modified
Description

The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.

Vendors
radykal
Products
fancy product designer
Ecosystems
WordPress
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news