Record summary

CVE-2021-25003 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 30, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

WPCargo Track & Trace

CVE List6.9.0 to < 6.9.0affected
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubbiulove0x/CVE-2021-25003Repository PoCby biulove0xStars: 6Not analyzed3 files

5.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress WPCargo Track & Trace <6.9.0 - Remote Code ExecutionCVSS 9.8

WordPress WPCargo Track & Trace plugin before 6.9.0 is susceptible to remote code execution, The plugin contains a file which can allow an attacker to write a PHP file anywhere on the web server, leading to possible remote code execution. This can allow an attacker to execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.

Impact

Successful exploitation of this vulnerability could lead to remote code execution, allowing an attacker to execute arbitrary code on the affected system.

Remediation

Update to the latest version of the WPCargo Track & Trace plugin (6.9.0 or higher) to mitigate this vulnerability.

WeaknessesCWE-434CWE-94
Authorstheamanrawat
Template tagscve2021cvercewpcargounauthwordpresswpwp-pluginwpscanintrusivewptaskforcevkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:wptaskforce:wpcargo_track_\&_trace:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2