PT-2021-15706 · Unknown · Responsive Menu
Chloe Chamberland
·
Published
2021-04-05
·
Updated
2021-04-08
·
CVE-2021-24160
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Reponsive Menu (free and Pro) versions prior to 4.0.4
Description:
The issue allows subscribers to upload zip archives containing malicious PHP files to the /rmp-menu/ directory. These files can then be accessed via the front end of the site, triggering remote code execution and potentially allowing an attacker to execute commands to further infect a WordPress site.
Recommendations:
For versions prior to 4.0.4, update to version 4.0.4 or later to resolve the issue. As a temporary workaround, consider restricting subscriber upload capabilities or disabling the ability to upload zip archives until the update is applied.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Responsive Menu