CVE-2021-24222
CRITICALWilliamluis Wp-curriculo Vitae Free < 6.3 - Unrestricted File Upload
Title source: ruleDescription
The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file extension restriction, leading to RCE.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://wpscan.com/vulnerability/4d715de6-8595-4da9-808a-04a28e409900
Third Party Advisory x_refsource_misc
https://github.com/jinhuang1102/CVE-ID-Reports/blob/145fc4e34c9b9799275c8e19d6b02f544c88126b/WP_Curriculo_Free.md
Scores
CVSS v3
9.8
EPSS
0.0566
EPSS Percentile
90.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
williamluis/wp-curriculo_vitae_free
< 6.3
Published
Apr 12, 2021
Tracked Since
Feb 18, 2026