Record summary

CVE-2021-24981 has a selected CVSS score of 7.5 (high). VulnCheck reports CVE-2021-24981 use in known ransomware campaigns.

Description

The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 16, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

Affected products and versions

2
ProductSourceVersion rangeStatus

Directorist – Business Directory Plugin

CVE List7.0.6.2 to < 7.0.6.2affected
VulnCheckVersion data not supplied

References

3