PT-2022-9561 · WordPress · Seur Oficial

José Aguilera

·

Published

2022-02-07

·

Updated

2022-02-11

·

CVE-2021-25004

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SEUR Oficial WordPress plugin versions prior to 1.7.2
Description The issue allows downloading any file from the web server without restriction after knowing the URL and a password that an administrator can see in the plugin settings page. This is possible because the plugin creates a PHP file with a random name when installed, which is used for support purposes.
Recommendations For versions prior to 1.7.2, update to version 1.7.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin settings page to minimize the risk of exploitation. Avoid using the password visible in the plugin settings page for any other purpose until the issue is resolved.

Exploit

Fix

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25004

Affected Products

Seur Oficial