First published: Thu May 06 2021(Updated: )
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate uploaded files, it could lead to RCE.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Business Directory Plugin | <5.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24179 is classified as a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2021-24179, update the Business Directory Plugin to version 5.11 or later.
CVE-2021-24179 can facilitate Cross-Site Request Forgery attacks and exploit file upload vulnerabilities leading to remote code execution.
Anyone using the Business Directory Plugin - Easy Listing Directories for WordPress versions before 5.11 is affected by CVE-2021-24179.
If you cannot update to fix CVE-2021-24179, you should disable the plugin and seek alternative solutions or plugins.