CVE-2021-24370: Fancy Product Designer < 4.6.9 - Unauthenticated Arbitrary File Upload and RCE
The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24370?
CVE-2021-24370 is a vulnerability in the Fancy Product Designer WordPress plugin before version 4.6.9 that allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.
How severe is CVE-2021-24370?
CVE-2021-24370 has a severity score of 9.8, indicating it is a critical vulnerability.
How can an attacker exploit CVE-2021-24370?
An attacker can exploit CVE-2021-24370 by uploading arbitrary files to the Fancy Product Designer plugin, which can lead to remote code execution.
What is the affected software for CVE-2021-24370?
The affected software is the Fancy Product Designer WordPress plugin before version 4.6.9.
How can I fix CVE-2021-24370?
To fix CVE-2021-24370, upgrade to version 4.6.9 or later of the Fancy Product Designer plugin.