CVE-2021-24216: All-in-One WP Migration < 7.41 - Admin+ Arbitrary File Upload to RCE
The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows administrators to upload PHP files on their site, even on multisite installations.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24216?
CVE-2021-24216 is classified as a high severity vulnerability due to improper file extension validation allowing PHP files to be uploaded.
How do I fix CVE-2021-24216?
To fix CVE-2021-24216, update the All-in-One WP Migration plugin to version 7.41 or later.
What types of installations are affected by CVE-2021-24216?
CVE-2021-24216 affects both single and multisite installations of the All-in-One WP Migration WordPress plugin.
What are the potential risks of CVE-2021-24216?
The risks of CVE-2021-24216 include unauthorized execution of PHP code which could lead to full site compromises.
Who is impacted by CVE-2021-24216?
Administrators using versions of the All-in-One WP Migration plugin prior to 7.41 are impacted by CVE-2021-24216.