← back
CVE-2021-24240

Business Hours Pro <= 5.5.0 - Unauthenticated Arbitrary File Upload to RCE

EPSS 3.0%CWE-434
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 3.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
22 Apr 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →