First published: Mon Jan 10 2022(Updated: )
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wow-company Button Generator | <2.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25052 is a vulnerability in the Button Generator WordPress plugin before version 2.3.3.
The severity of CVE-2021-25052 is high.
CVE-2021-25052 allows an attacker to include arbitrary PHP files using the admin menu page of the Button Generator plugin, potentially leading to remote code execution (RCE) via CSRF.
The Wow-company Button Generator plugin for WordPress versions up to and excluding 2.3.3 is affected by CVE-2021-25052.
To fix CVE-2021-25052, it is recommended to update the Button Generator plugin to version 2.3.3 or later.