CVE-2021-25052: Button Generator < 2.3.3 - RFI leading to RCE via CSRF
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-25052?
CVE-2021-25052 is a vulnerability in the Button Generator WordPress plugin before version 2.3.3.
What is the severity of CVE-2021-25052?
The severity of CVE-2021-25052 is high.
How does CVE-2021-25052 work?
CVE-2021-25052 allows an attacker to include arbitrary PHP files using the admin menu page of the Button Generator plugin, potentially leading to remote code execution (RCE) via CSRF.
What software is affected by CVE-2021-25052?
The Wow-company Button Generator plugin for WordPress versions up to and excluding 2.3.3 is affected by CVE-2021-25052.
How can CVE-2021-25052 be fixed?
To fix CVE-2021-25052, it is recommended to update the Button Generator plugin to version 2.3.3 or later.