PT-2022-9608 · WordPress · Button Generator

Krzysztof Zając

·

Published

2022-01-10

·

Updated

2022-01-14

·

CVE-2021-25052

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Button Generator WordPress plugin versions prior to 2.3.3
Description The issue allows for the inclusion of arbitrary files with PHP extension, as well as files using the data:// or http:// protocols, within the wow-company admin menu page. This can lead to CSRF RCE.
Recommendations For versions prior to 2.3.3, update to version 2.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the wow-company admin menu page to minimize the risk of exploitation. Avoid using the include() function with untrusted input until the issue is resolved.

Exploit

Fix

RCE

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25052

Affected Products

Button Generator