CVE-2021-36888
WordPress Image Hover Effects Ultimate plugin <= 9.6.1 - Unauthenticated Arbitrary Options Update leading to full website compromise
Record summary
CVE-2021-36888 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 16, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 28, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Image Hover Effects Ultimate (WordPress plugin)Browse Oxilab / Image Hover Effects Ultimate (WordPress plugin) | CVE List | <= 9.6.1 to ≤ 9.6.1 | affected |
image_hover_effectsBrowse blocksera / image_hover_effects | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALWordPress Image Hover Ultimate - Unauthenticated Settings UpdateCVSS 9.8
Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.
Impact
Attackers can fully compromise the website, leading to complete control and potential data theft or defacement.
Remediation
Update to the latest version of the plugin, newer than 9.6.1.
Source: ProjectDiscovery