Логотип exploitDog
bind:CVE-2021-24721
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24721

Количество 2

Количество 2

nvd логотип

CVE-2021-24721

больше 4 лет назад

The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated "translator" users being able to inject PHP code into files ending with .php in web accessible locations.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8mj6-23hc-v88f

больше 3 лет назад

The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated "translator" users being able to inject PHP code into files ending with .php in web accessible locations.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24721

The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated "translator" users being able to inject PHP code into files ending with .php in web accessible locations.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-8mj6-23hc-v88f

The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated "translator" users being able to inject PHP code into files ending with .php in web accessible locations.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу