← back
CVE-2021-24370

Fancy Product Designer < 4.6.9 - Unauthenticated Arbitrary File Upload and RCE

EPSS 47.1%CWE-434
The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →