PT-2021-23594 · WordPress · Wordpress Popular Posts
Jerome Bruandet
·
Published
2021-11-17
·
Updated
2024-09-16
·
CVE-2021-42362
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WordPress Popular Posts versions up to and including 5.3.2
Description
The WordPress Popular Posts plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file. This makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution.
Recommendations
For versions up to and including 5.3.2, update to a version that includes the fix for the arbitrary file upload vulnerability. As a temporary workaround, consider restricting access to the ~/src/Image.php file to minimize the risk of exploitation. Additionally, restrict contributor level access and above to prevent attackers from uploading malicious files.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress Popular Posts