Record summary

CVE-2021-24220 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0 register a REST API endpoint to compress images using the Kraken image optimization engine. By supplying a crafted request in combination with data inserted using the Option Update vulnerability, it was possible to use this endpoint to retrieve malicious code from a remote URL and overwrite an existing file on the site with it or create a new file.This includes executable PHP files that contain malicious code.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 24, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

11
ProductSourceVersion rangeStatus
CVE List2.0.0 to < 2.0.0affected
CVE List2.0.0 to < 2.0.0affected
CVE List2.0.0 to < 2.0.0affected
CVE List2.0.0 to < 2.0.0affected
CVE List2.0.0 to < 2.0.0affected
CVE List2.0.0 to < 2.0.0affected
CVE List2.0.0 to < 2.0.0affected
CVE List2.0.0 to < 2.0.0affected
CVE List2.0.0 to < 2.0.0affected
CVE List2.0.0 to < 2.0.0affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALMultiple Thrive Themes < 2.0.0 - Arbitrary File UploadCVSS 9.1

Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0 register a REST API endpoint to compress images using the Kraken image optimization engine. By supplying a crafted request in combination with data inserted using the Option Update vulnerability, it was possible to use this endpoint to retrieve malicious code from a remote URL and overwrite an existing file on the site with it or create a new file.This includes executable PHP files that contain malicious code.

Impact

Attackers can execute arbitrary PHP code, potentially leading to full site compromise and malicious control.

Remediation

Update all affected themes to version 2.0.0 or later to fix the vulnerability.

WeaknessesCWE-434
Authorspussycat0x
Template tagscvecve2021wordpresswpwpscanwp-themethrivepassivevkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CPE: cpe:2.3:a:thrivethemes:focusblog:*:*:*:*:*:wordpress_:*:*

Source: ProjectDiscovery

References

3