← back
CVE-2021-24537

Similar Posts <= 3.1.5 - Admin+ Arbitrary PHP Code Execution

EPSS 1.5%CWE-94
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
08 Nov 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened environment (ie with DISALLOW_FILE_EDIT, DISALLOW_FILE_MODS and DISALLOW_UNFILTERED_HTML set to true) via the 'widget_rrm_similar_posts_condition' widget setting of the plugin.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →