← back
CVE-2021-24370observed exploitationCWE-434

Fancy Product Designer < 4.6.9 - Unauthenticated Arbitrary File Upload and RCE

52Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 47%
from disclosure to weapon
Published on NVDJun 21
VulnCheckJun 1
exploitation probability
47%top 1% of all CVEs
observed exploitation
yesVulnCheck
The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.