nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24644 CVE-2021-24644
HIGHNuclei
Images to WebP < 1.9 - Authenticated Local File Inclusion
Record summary
CVE-2021-24644 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 19, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Images to WebP | CVE List | 1.9 to < 1.9 | affected |
images_to_webpBrowse imagestowebp_project / images_to_webp | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHImages to WebP < 1.9 - Authenticated Local File InclusionCVSS 7.5
The Images to WebP WordPress plugin before version 1.9 did not validate or sanitize the tab parameter before using it in the include() function.
Impact
Authenticated attackers can read arbitrary local files from the server via path traversal, potentially exposing sensitive configuration files, credentials, and system information.
Remediation
Fixed in 1.9
WeaknessesCWE-22
AuthorsSourabh-Sahu
Template tagswpscancvecve2021wordpresswp-pluginimages-to-webplfiauthenticatedintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:imagestowebp_project:images_to_webp:*:*:*:*:*:wordpress:*:*
https://wpscan.com/vulnerability/5a363eeb-9510-4535-97e2-9dfd3b10d511/ https://nvd.nist.gov/vuln/detail/CVE-2021-24644
Source: ProjectDiscovery
References
2wpscan.com
https://wpscan.com/vulnerability/5a363eeb-9510-4535-97e2-9dfd3b10d511