PT-2021-16016 · WordPress · Shopp

Fellipe Oliveira

+1

·

Published

2021-09-13

·

Updated

2021-09-23

·

CVE-2021-24493

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shopp WordPress plugin versions 1.4 and earlier
Description The issue concerns the lack of security measures in the shopp upload file AJAX action, allowing both unauthenticated and authenticated users to upload malicious files, such as PHP files, without restriction. This can lead to remote code execution (RCE) as unauthenticated users can upload arbitrary files.
Recommendations For Shopp WordPress plugin versions 1.4 and earlier, as a temporary workaround, consider disabling the shopp upload file AJAX action until a patch is available. Restrict access to file upload functionality to minimize the risk of exploitation. Avoid using the file upload feature in the affected plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24493

Affected Products

Shopp