codecanyon.net
https://codecanyon.net/item/business-hours-pro-wordpress-plugin/9414879 CVE-2021-24240
CRITICAL
Business Hours Pro <= 5.5.0 - Unauthenticated Arbitrary File Upload to RCE
Record summary
CVE-2021-24240 has a selected CVSS score of 9.8 (critical).
Description
The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 2, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Business Hours Pro | CVE List | 5.5.0 to ≤ 5.5.0 | affected |
business_hours_proBrowse aivahthemes / business_hours_pro | VulnCheck | Version data not supplied | |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24240 wpscan.comConfirmation
https://wpscan.com/vulnerability/10528cb2-12a1-43f7-9b7d-d75d18fdf5bb