Record summary

CVE-2021-24370 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 1, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Fancy Product Designer

CVE List4.6.9 to < 4.6.9affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress Fancy Product Designer <4.6.9 - Arbitrary File UploadCVSS 9.8

WordPress Fancy Product Designer plugin before 4.6.9 is susceptible to an arbitrary file upload. An attacker can upload malicious files and execute code on the server, modify data, and/or gain full control over a compromised system without authentication.

Impact

Attackers can upload malicious files and execute arbitrary code on the target system.

Remediation

Update WordPress Fancy Product Designer plugin to version 4.6.9 or later to fix the vulnerability.

WeaknessesCWE-434
Authorspikpikcu
Template tagscve2021cvewordpresswpseclistswpscanrcewp-pluginfancyproductradykalvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:radykal:fancy_product_designer:*:*:*:*:*:wordpress:*:*
Google: inurl:“/wp-content/plugins/fancy-product-designer”

Source: ProjectDiscovery

References

6