CVE-2021-4354: PWA for WP & AMP <= 1.7.32 - Arbitrary File Upload
The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwpsplashscreenuploader function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-4354?
CVE-2021-4354 is the identification number for a vulnerability found in the PWA for WP & AMP for WordPress plugin.
What is the severity of CVE-2021-4354?
The severity of CVE-2021-4354 is high with a CVSS score of 8.8.
What is the affected software of CVE-2021-4354?
The affected software is the PWA for WP & AMP for WordPress plugin up to and including version 1.7.32.
What is the vulnerability in CVE-2021-4354?
The vulnerability in CVE-2021-4354 is arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function.
How can an attacker exploit CVE-2021-4354?
Authenticated attackers can exploit CVE-2021-4354 by uploading arbitrary files on the affected websites.