Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24209

Опубликовано: 05 апр. 2021
Источник: nvd
CVSS3: 7.2
CVSS2: 9
EPSS Низкий

Описание

The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:automattic:wp_super_cache:*:*:*:*:*:wordpress:*:*
Версия до 1.7.2 (исключая)

EPSS

Процентиль: 85%
0.02352
Низкий

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.2
github
больше 3 лет назад

The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.

EPSS

Процентиль: 85%
0.02352
Низкий

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-94