CVE-2021-24284

CRITICAL EXPLOITED IN THE WILD NUCLEI

Kaswara < 3.0.1 - Unrestricted File Upload

Title source: rule

Description

The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as PHP.

Nuclei Templates (1)

WordPress Kaswara Modern VC Addons <=3.0.1 - Arbitrary File Upload
CRITICALby lamscun,pussycat0x,pdteam

Scores

CVSS v3 9.8
EPSS 0.6800
EPSS Percentile 98.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-12-24
InTheWild.io 2022-07-13
CWE
CWE-434
Status published
Products (1)
kaswara_project/kaswara < 3.0.1
Published May 14, 2021
Tracked Since Feb 18, 2026