CVE-2021-24284
CRITICAL EXPLOITED IN THE WILD NUCLEIKaswara < 3.0.1 - Unrestricted File Upload
Title source: ruleDescription
The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as PHP.
Nuclei Templates (1)
WordPress Kaswara Modern VC Addons <=3.0.1 - Arbitrary File Upload
CRITICALby lamscun,pussycat0x,pdteam
References (3)
Scores
CVSS v3
9.8
EPSS
0.6800
EPSS Percentile
98.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2023-12-24
InTheWild.io
2022-07-13
CWE
CWE-434
Status
published
Products (1)
kaswara_project/kaswara
< 3.0.1
Published
May 14, 2021
Tracked Since
Feb 18, 2026