Record summary

CVE-2021-36888 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 16, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 28, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Image Hover Effects Ultimate (WordPress plugin)

Browse Oxilab / Image Hover Effects Ultimate (WordPress plugin)
CVE List<= 9.6.1 to ≤ 9.6.1affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress Image Hover Ultimate - Unauthenticated Settings UpdateCVSS 9.8

Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.

Impact

Attackers can fully compromise the website, leading to complete control and potential data theft or defacement.

Remediation

Update to the latest version of the plugin, newer than 9.6.1.

WeaknessesCWE-284
Authorsriteshs4hu
Template tagscvecve2021wpscanwp-pluginwordpressimagehoverintrusiveunauthvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:blocksera:image_hover_effects:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3