CVE-2021-24123: PowerPress < 8.3.8 - Authenticated Arbitrary File Upload leading to RCE
Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2021-24123?
The vulnerability CVE-2021-24123 is an arbitrary file upload vulnerability in the PowerPress WordPress plugin.
What is the severity of CVE-2021-24123?
The severity of CVE-2021-24123 is high with a severity value of 7.2.
Which versions of the PowerPress WordPress plugin are affected by CVE-2021-24123?
Versions of the PowerPress WordPress plugin before 8.3.8 are affected by CVE-2021-24123.
How does CVE-2021-24123 work?
CVE-2021-24123 allows high privilege accounts (admin+) to upload arbitrary files, such as PHP, leading to remote code execution.
How can CVE-2021-24123 be mitigated?
To mitigate CVE-2021-24123, it is recommended to update the PowerPress WordPress plugin to version 8.3.8 or later.