Record summary

CVE-2021-25052 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Button Generator – easily Button Builder

CVE List2.3.3 to < 2.3.3affected

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Button Generator <2.3.3 - Remote File InclusionCVSS 8.8

WordPress Button Generator before 2.3.3 within the wow-company admin menu page allows arbitrary file inclusion with PHP extensions (as well as with data:// or http:// protocols), thus leading to cross-site request forgery and remote code execution.

Impact

An attacker can exploit this vulnerability to execute arbitrary code on the target system.

Remediation

Update to the latest version of the WordPress Button Generator plugin (2.3.3) to fix the remote file inclusion vulnerability.

WeaknessesCWE-352
Authorscckuailong
Template tagscve2021cvewp-pluginauthenticatedwpscanrfiwpwordpresswow-companyvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:wow-company:button_generator:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3