WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 8.8epss 80%
from disclosure to weapon0 days
Published on NVDNov 17
1st PoCJul 14
metasploitJun 11
exploitation probability
80%top 1% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
WordPress Popular Posts · WordPress Popular Postspublic PoCs found — 4
exploitdbwww.exploit-db.com/exploits/50129unverifiedgithubgithub.com/simonecris/CVE-2021-42362-PoC★ 0githubgithub.com/samiba6/CVE-2021-42362★ 0cve_referencepacketstormsecurity.com/files/165376/WordPress-Popular-Posts-5.3.2-Remote-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/165376/WordPress-Popular-Posts-5.3.2-Remote-Code-Execution.htmlhttps://blog.nintechnet.com/improper-input-validation-fixed-in-wordpress-popular-posts-plugin/https://github.com/cabrerahector/wordpress-popular-posts/commit/d9b274cf6812eb446e4103cb18f69897ec6fe601https://plugins.trac.wordpress.org/changeset/2542638/wordpress-popular-posts/trunk/src/Image.phphttps://wpscan.com/vulnerability/bd4f157c-a3d7-4535-a587-0102ba4e3009https://www.wordfence.com/vulnerability-advisories/#CVE-2021-42362