CVE-2021-24981

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
21/12/2021
Last modified:
27/12/2021

Description

The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wpwax:directorist:*:*:*:*:*:wordpress:*:* 7.0.6.2 (excluding)