PT-2021-3534 · WordPress · The Business Directory Plugin

0Xb9

·

Published

2021-05-05

·

Updated

2021-12-08

·

CVE-2021-24248

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Business Directory Plugin versions prior to 5.11.1
Description The issue is related to unrestricted file upload of dangerous types in the Business Directory plugin for WordPress. This could allow a remote attacker to read arbitrary files in the configuration directory. The problem stems from improper checking of imported files, using a blacklist approach to forbid certain extensions, which can be bypassed by importing an archive containing a malicious file, such as a .php4 file, leading to remote code execution.
Recommendations For versions prior to 5.11.1, update to version 5.11.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the file upload functionality to minimize the risk of exploitation. Avoid using the plugin's file import feature until the issue is resolved.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03585
CVE-2021-24248

Affected Products

The Business Directory Plugin