PT-2021-3415 · WordPress · Wordpress Classifieds Plugin

Jin Huang

+1

·

Published

2021-05-05

·

Updated

2021-05-14

·

CVE-2021-24253

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Classyfrieds WordPress plugin versions prior to 3.8
Description The issue is related to unrestricted file uploads of dangerous types. Exploitation of this issue may allow a remote attacker to upload and execute arbitrary files. Specifically, the plugin does not properly check uploaded files when an authenticated user adds a listing, only verifying the content-type in the request. This allows any authenticated user to upload arbitrary PHP files via the Add Listing feature, leading to remote code execution.
Recommendations For Classyfrieds WordPress plugin versions prior to 3.8, update to a version that properly checks and restricts file uploads to prevent arbitrary file execution. As a temporary workaround, consider disabling the file upload feature in the Add Listing section of the plugin until a secure update is available. Restrict access to the plugin's file upload functionality to minimize the risk of exploitation.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03267
CVE-2021-24253

Affected Products

Wordpress Classifieds Plugin