Record summary

CVE-2021-34624 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 5, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 15, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List3.0.0 - 3.1.3affected

Default status: unknown

CVE List, VulnCheck3.0.0 to ≤ 3.1.3affected

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress ProfilePress 3.0-3.1.3 - Arbitrary File UploadCVSS 9.8

A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3.

Impact

Unauthenticated attackers can upload arbitrary files including PHP files during registration, achieving remote code execution and complete server compromise.

Remediation

Update to ProfilePress version 3.1.4 or later

WeaknessesCWE-434
AuthorsSourabh-Sahu
Template tagscvecve2021wordpresswp-pluginwpwpscanwp-user-avatarprofilepressrcefile-uploadunauthintrusive
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:properfraction:profilepress:*:*:*:*:*:wordpress:*:*
Shodan: http.component:"profilepress"
FOFA: body="/wp-content/plugins/wp-user-avatar/"

Source: ProjectDiscovery

References

2