Record summary

CVE-2021-24160 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC.

Description

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List4.0.4 to < 4.0.4affected

Responsive Menu – Create Mobile-Friendly Menu

Browse ExpressTech / Responsive Menu – Create Mobile-Friendly Menu
CVE List4.0.4 to < 4.0.4affected

Proofs of concept

1

Repository PoCs

GitHublikeww/Exploit-CVE-2021-24160Repository PoCby likewwStars: 0Not analyzed2 files

14.9 KiB

GitHub

PoC details

References

3