Vulnerability Description
The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Imagements Project | Imagements | <= 1.2.5 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/8f24e74f-60e3-4100-9ab2-ec31b9c9cdeaExploitThird Party Advisory
- https://wpscan.com/vulnerability/8f24e74f-60e3-4100-9ab2-ec31b9c9cdeaExploitThird Party Advisory
FAQ
What is CVE-2021-24236?
CVE-2021-24236 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated a...
How severe is CVE-2021-24236?
CVE-2021-24236 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-24236?
Check the references section above for vendor advisories and patch information. Affected products include: Imagements Project Imagements.