CVE-2021-24537
Similar Posts <= 3.1.5 - Admin+ Arbitrary PHP Code Execution
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
08 Nov 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened environment (ie with DISALLOW_FILE_EDIT, DISALLOW_FILE_MODS and DISALLOW_UNFILTERED_HTML set to true) via the 'widget_rrm_similar_posts_condition' widget setting of the plugin.
Affected products
Unknown · Similar Posts – Best Related Posts Plugin for WordPressWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →