nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24160 CVE-2021-24160
HIGH
Responsive Menu 4.0.0 - 4.0.3 - Authenticated Arbitrary File Upload
Record summary
CVE-2021-24160 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC.
Description
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Responsive Menu ProBrowse ExpressTech / Responsive Menu Pro | CVE List | 4.0.4 to < 4.0.4 | affected |
Responsive Menu – Create Mobile-Friendly MenuBrowse ExpressTech / Responsive Menu – Create Mobile-Friendly Menu | CVE List | 4.0.4 to < 4.0.4 | affected |
Proofs of concept
1Repository PoCs
GitHublikeww/Exploit-CVE-2021-24160Repository PoCby likewwStars: 0Not analyzed2 files
References
3wpscan.comConfirmation
https://wpscan.com/vulnerability/066ba5d4-4aaa-4462-b106-500c1f291c37 wordfence.com
https://www.wordfence.com/blog/2021/02/multiple-vulnerabilities-patched-in-responsive-menu-plugin