First published: Thu May 06 2021(Updated: )
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example, leading to RCE
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Easy Listing Directories Business Directory Plugin | <5.11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24248 has been classified with a high severity level due to its ability to allow remote code execution.
To mitigate CVE-2021-24248, update the Business Directory Plugin to version 5.11.1 or later.
CVE-2021-24248 exploits improper file checks when importing files, allowing potentially dangerous file types to be uploaded.
Any WordPress site using the Business Directory Plugin prior to version 5.11.1 is affected by CVE-2021-24248.
CVE-2021-24248 can lead to a remote code execution attack, allowing attackers to execute malicious code on the server.