Record summary

CVE-2021-24311 has a selected CVSS score of 8.8 (high).

Description

The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any authenticated users.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 5, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

2
ProductSourceVersion rangeStatus

External Media

CVE List1.0.34 to < 1.0.34affected
VulnCheckVersion data not supplied

References

3