← back
CVE-2021-25003observed exploitationCWE-94

WPCargo < 6.9.0 - Unauthenticated RCE

72Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 56%
from disclosure to weapon104 days
Published on NVDMar 14
1st PoC+104d
VulnCheck+626d
exploitation probability
56%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.