AivahThemes Vulnerabilities and Affected Products
Vulnerabilities associated with business_hours_pro.
Products
Clear product- Anona3 vulnerabilities
- Car Zone2 vulnerabilities
- business_hours_pro1 vulnerability
- Hostme v21 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-24240CRITICAL | Business Hours Pro <= 5.5.0 - Unauthenticated Arbitrary File Upload to RCEThe Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability. CWE-434Apr 22, 2021 | CVSS9.8v3.1 | EPSS3.04% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |