CVE-2021-25052
Button Generator < 2.3.3 - RFI leading to RCE via CSRF
Record summary
CVE-2021-25052 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Button Generator – easily Button Builder | CVE List | 2.3.3 to < 2.3.3 | affected |
Nuclei templates
1ProjectDiscoveryHIGHWordPress Button Generator <2.3.3 - Remote File InclusionCVSS 8.8
WordPress Button Generator before 2.3.3 within the wow-company admin menu page allows arbitrary file inclusion with PHP extensions (as well as with data:// or http:// protocols), thus leading to cross-site request forgery and remote code execution.
Impact
An attacker can exploit this vulnerability to execute arbitrary code on the target system.
Remediation
Update to the latest version of the WordPress Button Generator plugin (2.3.3) to fix the remote file inclusion vulnerability.
Source: ProjectDiscovery