CVE-2021-38360: wp-publications <= 0.0 Local File Include
The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the QFILE parameter found in the ~/bibtexbrowser.php file which allows attackers to include local zip files and achieve remote code execution, in versions up to and including 0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
wordpress/wp-publicationsfrom your environment.Uninstall the wp-publications WordPress plugin from the WordPress site (vulnerable in versions up to and including 0.0 via Q_FILE in ~/bibtexbrowser.php allowing local file inclusion and remote code execution).
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38360?
CVE-2021-38360 has a high severity rating due to its potential to enable remote code execution through local file inclusion.
How do I fix CVE-2021-38360?
To fix CVE-2021-38360, update the wp-publications WordPress plugin to the latest version that addresses this vulnerability.
What types of attacks could exploit CVE-2021-38360?
CVE-2021-38360 could be exploited by attackers to include local zip files, potentially leading to remote code execution.
Which versions of the wp-publications plugin are affected by CVE-2021-38360?
CVE-2021-38360 affects all versions of the wp-publications plugin up to and including version 0.0.
Where can I find more information about CVE-2021-38360?
More information about CVE-2021-38360 can typically be found in technical advisories from security analysts and vulnerability databases.