← voltar
CVE-2021-39352highCWE-434

Catch Themes Demo Import <= 1.7 Admin+ Arbitrary File Upload

48Vexday Risk Score

Corrija em breve. Ela tem exploit funcional público.

ssvc Attendcvss 7.2epss 56%
da publicação à arma0 dias
Publicada no NVD21 de out.
metasploit21 de out.
probabilidade de exploração
56%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges to upload malicious files that can be used to achieve remote code execution.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H