First published: Mon Jan 10 2022(Updated: )
The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wow-company Wp Coder | <2.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25053 is a vulnerability in the WP Coder WordPress plugin that allows for arbitrary file inclusion and can lead to CSRF RCE.
CVE-2021-25053 has a severity keyword of 'high' and a severity value of 8.8.
The affected software is the WP Coder WordPress plugin before version 2.5.2 by Wow-company.
To fix CVE-2021-25053, update the WP Coder WordPress plugin to version 2.5.2 or later.
The CWE for CVE-2021-25053 is 352 (Cross-Site Request Forgery).