CVE-2021-42362

HIGH

Wordpress Popular Posts < 5.3.2 - Unrestricted File Upload

Title source: rule

Description

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.

Exploits (4)

exploitdb WORKING POC
by Simone Cristofaro · pythonwebappsphp
https://www.exploit-db.com/exploits/50129
nomisec WORKING POC
by samiba6 · poc
https://github.com/samiba6/CVE-2021-42362
nomisec WORKING POC
by simonecris · poc
https://github.com/simonecris/CVE-2021-42362-PoC
metasploit WORKING POC NORMAL
by h00die, Simone Cristofaro, Jerome Bruandet · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/wp_popular_posts_rce.rb

Scores

CVSS v3 8.8
EPSS 0.7755
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
wordpress_popular_posts_project/wordpress_popular_posts < 5.3.2
Published Nov 17, 2021
Tracked Since Feb 18, 2026