CVE-2021-25051: Modal Window < 5.2.2 - RFI leading to RCE via CSRF
The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2021-25051.
What is the severity of CVE-2021-25051?
The severity of CVE-2021-25051 is high.
What is the affected software for CVE-2021-25051?
The affected software for CVE-2021-25051 is the Modal Window WordPress plugin before version 5.2.2 by Wow-company.
What is the vulnerability description for CVE-2021-25051?
CVE-2021-25051 is a vulnerability in the Modal Window WordPress plugin before version 5.2.2 which allows for inclusion of arbitrary PHP files, leading to CSRF RCE.
Are there any references related to CVE-2021-25051?
Yes, you can find more information about CVE-2021-25051 at the following references: [1] https://plugins.trac.wordpress.org/changeset/2641645/modal-window, [2] https://wpscan.com/vulnerability/566ff8dc-f820-412b-b2d3-fa789bce528e