Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lostbytes1

#34877of 53,619
7.5Total CVSS
Vulnerabilities · 1
PT-2021-16392
7.5
2021-12-21
WordPress · Directorist · CVE-2021-24981
Name of the Vulnerable Software and Affected Versions: The Directorist WordPress plugin versions prior to 7.0.6.2 Description: The issue allows for Cross-Site Request Forgery to Remote File Upload, leading to arbitrary PHP shell uploads in the wp-content/plugins directory. This can be exploited to upload malicious files, potentially allowing attackers to execute arbitrary code on the server. Recommendations: For versions prior to 7.0.6.2, update to version 7.0.6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the wp-content/plugins directory to minimize the risk of exploitation.