Record summary

CVE-2021-24644 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 19, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Images to WebP

CVE List1.9 to < 1.9affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHImages to WebP < 1.9 - Authenticated Local File InclusionCVSS 7.5

The Images to WebP WordPress plugin before version 1.9 did not validate or sanitize the tab parameter before using it in the include() function.

Impact

Authenticated attackers can read arbitrary local files from the server via path traversal, potentially exposing sensitive configuration files, credentials, and system information.

Remediation

Fixed in 1.9

WeaknessesCWE-22
AuthorsSourabh-Sahu
Template tagswpscancvecve2021wordpresswp-pluginimages-to-webplfiauthenticatedintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:imagestowebp_project:images_to_webp:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2