ZeroHour

CVE-2021-24684

PoC
CVSS 3.1
8.8 high
EPSS
4%p91
Published
()
Modified
Description

The WordPress PDF Light Viewer Plugin WordPress plugin before 1.4.12 allows users with Author roles to execute arbitrary OS command on the server via OS Command Injection when invoking Ghostscript.

Vendors
teamlead
Products
pdf-light-viewer
Ecosystems
WordPress
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.