WordPress · Directorist · CVE-2021-24981
Name of the Vulnerable Software and Affected Versions:
The Directorist WordPress plugin versions prior to 7.0.6.2
Description:
The issue allows for Cross-Site Request Forgery to Remote File Upload, leading to arbitrary PHP shell uploads in the wp-content/plugins directory. This can be exploited to upload malicious files, potentially allowing attackers to execute arbitrary code on the server.
Recommendations:
For versions prior to 7.0.6.2, update to version 7.0.6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the wp-content/plugins directory to minimize the risk of exploitation.