CVE-2021-24254

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
06/05/2021
Last modified:
14/05/2021

Description

The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:college_publisher_import_project:college_publisher_import:*:*:*:*:*:wordpress:*:* 0.1 (including)