CVE-2021-24248: Business Directory Plugin < 5.11.1 - Authenticated PHP4 Upload to RCE
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example, leading to RCE
Other sources
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example, leading to RCE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24248?
CVE-2021-24248 has been classified with a high severity level due to its ability to allow remote code execution.
How do I fix CVE-2021-24248?
To mitigate CVE-2021-24248, update the Business Directory Plugin to version 5.11.1 or later.
What does CVE-2021-24248 exploit?
CVE-2021-24248 exploits improper file checks when importing files, allowing potentially dangerous file types to be uploaded.
Who is affected by CVE-2021-24248?
Any WordPress site using the Business Directory Plugin prior to version 5.11.1 is affected by CVE-2021-24248.
What kind of attack can CVE-2021-24248 lead to?
CVE-2021-24248 can lead to a remote code execution attack, allowing attackers to execute malicious code on the server.