CVE-2021-24240

CRITICAL EXPLOITED

Aivahthemes Business Hours Pro < 5.5.0 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.

References (2)

Core 2
Core References
Product, Third Party Advisory x_refsource_misc
https://codecanyon.net/item/business-hours-pro-wordpress-plugin/9414879

Scores

CVSS v3 9.8
EPSS 0.0807
EPSS Percentile 92.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2021-04-02
CWE
CWE-434
Status published
Products (1)
aivahthemes/business_hours_pro < 5.5.0
Published Apr 22, 2021
Tracked Since Feb 18, 2026