CVE-2021-25053: WP Coder < 2.5.2 - RFI leading to RCE via CSRF
Published Jan 10, 2022
·Updated
The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
Affected Software
1 affected component
Wow-Company WP Coder WordPress<2.5.2
Remediation
Event History
Jan 10, 2022
CVE Published
via MITRE·03:30 PM
Data Sourced
via MITRE·03:30 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-25053?
CVE-2021-25053 is a vulnerability in the WP Coder WordPress plugin that allows for arbitrary file inclusion and can lead to CSRF RCE.
2
How severe is CVE-2021-25053?
CVE-2021-25053 has a severity keyword of 'high' and a severity value of 8.8.
3
What is the affected software?
The affected software is the WP Coder WordPress plugin before version 2.5.2 by Wow-company.
4
How can I fix CVE-2021-25053?
To fix CVE-2021-25053, update the WP Coder WordPress plugin to version 2.5.2 or later.
5
What is the CWE for CVE-2021-25053?
The CWE for CVE-2021-25053 is 352 (Cross-Site Request Forgery).