CVE-2021-24284
Kaswara Modern VC Addons <= 3.0.1 - Unauthenticated Arbitrary File Upload
Record summary
CVE-2021-24284 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as PHP.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 24, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Kaswara Modern VC AddonsBrowse SayenThemes / Kaswara Modern VC Addons | CVE List | 3.0.1 to ≤ 3.0.1 | affected |
| VulnCheck | Version data not supplied | ||
Nuclei templates
1ProjectDiscoveryCRITICALWordPress Kaswara Modern VC Addons <=3.0.1 - Arbitrary File UploadCVSS 9.8
WordPress Kaswara Modern VC Addons plugin through 3.0.1 is susceptible to an arbitrary file upload. The plugin allows unauthenticated arbitrary file upload via the uploadFontIcon AJAX action, which can be used to obtain code execution. The supplied zipfile is unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as PHP.
Impact
Successful exploitation of this vulnerability can result in unauthorized remote code execution on the affected WordPress website.
Remediation
Update to the latest version of Kaswara Modern VC Addons plugin (>=3.0.2) to mitigate this vulnerability.
Source: ProjectDiscovery