CVE-2021-24430
HIGHSpeed Booster Pack < 4.2.0 - Remote Code Execution via Unvalidated Caching Settings
Title source: llmDescription
The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_query_strings settings before outputting them in a PHP file, which could lead to RCE
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/945d6d2e-fa25-42c0-a7b4-b1794732a0df
Various Sources x_refsource_misc
https://m0ze.ru/vulnerability/%5B2021-05-10%5D-%5BWordPress%5D-%5BCWE-94%5D-Speed-Booster-Pack-WordPress-Plugin-v4.2.0-beta.txt
Scores
CVSS v3
7.2
EPSS
0.0172
EPSS Percentile
74.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (1)
optimocha/speed_booster_pack
< 4.2.0
Published
Aug 02, 2021
Tracked Since
Feb 18, 2026