nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-4455 CVE-2021-4455
CRITICAL
Wordpress Plugin Smart Product Review <= 1.0.4 - Unauthenticated Arbitrary File Upload
Record summary
CVE-2021-4455 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 21, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Wordpress Plugin Smart Product ReviewBrowse Codeflist / Wordpress Plugin Smart Product ReviewDefault status: unaffected | CVE List | Through 1.0.4 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordpress Plugin Smart Product Review 1.0.4 - Arbitrary File UploadExploitDB exploitby Keyvan HardaniNot analyzed1 file
References
3exploit-db.com
https://www.exploit-db.com/exploits/50533 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/1de9183c-95b9-4500-85e2-08dcee956360?source=cve