Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24189

Опубликовано: 14 мая 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wp-buy:captchinoo:*:*:*:*:*:wordpress:*:*
Версия до 2.4 (исключая)

EPSS

Процентиль: 69%
0.00603
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-285
NVD-CWE-noinfo

Связанные уязвимости

github
больше 3 лет назад

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

EPSS

Процентиль: 69%
0.00603
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-285
NVD-CWE-noinfo