CVE-2021-24160

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
05/04/2021
Last modified:
08/04/2021

Description

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:expresstech:responsive_menu:*:*:*:*:free:wordpress:*:* 4.0.4 (excluding)
cpe:2.3:a:expresstech:responsive_menu:*:*:*:*:pro:wordpress:*:* 4.0.4 (excluding)