CVE-2021-24161: Responsive Menu < 4.0.4 - CSRF to Arbitrary File Upload
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24161?
CVE-2021-24161 is a vulnerability in the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4 that allows attackers to achieve remote code execution by tricking an administrator into uploading malicious PHP files.
How can an attacker exploit CVE-2021-24161?
An attacker can exploit CVE-2021-24161 by crafting a request and tricking an administrator into uploading a zip archive containing malicious PHP files.
What is the severity of CVE-2021-24161?
The severity of CVE-2021-24161 is high, with a severity value of 8.8.
How do I fix CVE-2021-24161?
To fix CVE-2021-24161, update the Reponsive Menu plugins to version 4.0.4 or newer.
Is there any additional information available about CVE-2021-24161?
Yes, you can find additional information about CVE-2021-24161 at the following references: [link1] [link2]