Record summary

CVE-2021-24212 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 21, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

WooCommerce Help Scout

CVE List2.9.1 to < 2.9.1affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWooCommerce Help Scout - Arbitrary File UploadCVSS 9.8

WooCommerce Help Scout plugin before version 2.9.1 contains an unrestricted file upload vulnerability. The vulnerability allows unauthenticated users to upload arbitrary files to the server which by default will end up in wp-content/uploads/hstmp/ directory, potentially leading to remote code execution.

Impact

Unauthenticated attackers can upload malicious files, potentially leading to remote code execution or site compromise.

Remediation

Update to version 2.9.1 or later.

WeaknessesCWE-434
Authorsritikchaddha
Template tagscvecve2021wpwordpresswp-pluginfile-uploadrcewoocommerce-help-scoutvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
FOFA: body="/wp-content/plugins/woocommerce-help-scout"

Source: ProjectDiscovery

References

3