← Back to CVEs
CVE-2021-24161
HIGH8.8
Description
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.
CVE Details
CVSS v3.1 Score8.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
Published4/5/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
expresstech:responsive_menu
Weaknesses (CWE)
CWE-352CWE-352
References
https://wpscan.com/vulnerability/efca27e0-bdb6-4497-8330-081f909d6933(contact@wpscan.com)
https://www.wordfence.com/blog/2021/02/multiple-vulnerabilities-patched-in-responsive-menu-plugin/(contact@wpscan.com)
https://wpscan.com/vulnerability/efca27e0-bdb6-4497-8330-081f909d6933(af854a3a-2127-422b-91ae-364da2661108)
https://www.wordfence.com/blog/2021/02/multiple-vulnerabilities-patched-in-responsive-menu-plugin/(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.