First published: Mon Mar 28 2022(Updated: )
The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code execution.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Iptanus WordPress File Upload | <4.16.3 | |
Iptanus WordPress File Upload | <4.16.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24962 is a vulnerability found in the WordPress File Upload Free and Pro WordPress plugins before version 4.16.3.
The severity of CVE-2021-24962 is high, with a CVSS score of 8.8.
CVE-2021-24962 allows users with a role as low as Contributor to perform path traversal and upload malicious PHP code disguised as an image within the plugin's directory.
Versions of the WordPress File Upload plugins up to and excluding 4.16.3 are affected by CVE-2021-24962.
To fix CVE-2021-24962, update the WordPress File Upload plugins to version 4.16.3 or later.