CVE-2021-24370
Fancy Product Designer < 4.6.9 - Unauthenticated Arbitrary File Upload and RCE
Record summary
CVE-2021-24370 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 1, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Fancy Product Designer | CVE List | 4.6.9 to < 4.6.9 | affected |
fancy_product_designerBrowse radykal / fancy_product_designer | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALWordPress Fancy Product Designer <4.6.9 - Arbitrary File UploadCVSS 9.8
WordPress Fancy Product Designer plugin before 4.6.9 is susceptible to an arbitrary file upload. An attacker can upload malicious files and execute code on the server, modify data, and/or gain full control over a compromised system without authentication.
Impact
Attackers can upload malicious files and execute arbitrary code on the target system.
Remediation
Update WordPress Fancy Product Designer plugin to version 4.6.9 or later to fix the vulnerability.
Source: ProjectDiscovery