CVE-2021-24721 Information
Jun 07, 2022
cve
Description
The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file which can be renamed to an extension ending in .php resulting in authenticated ranslator\ users being able to inject PHP code into files ending with .php in web accessible locations.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Reference
https://wpscan.com/vulnerability/bc7d4774-fce8-4b0b-8015-8ef4c5b02d38
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
6.5
Share on: