ZeroHour

CVE-2021-24644

PoC
CVSS 3.1
7.5 high
EPSS
5%p92
Published
()
Modified
Description

The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue

Vendors
imagestowebp project
Products
images to webp
Ecosystems
WordPress
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.