Vulnerability Description
The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Thinkupthemes | Responsive Vector Maps | < 6.4.2 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/c6bb12b1-6961-40bd-9110-edfa9ee41a18ExploitThird Party Advisory
- https://wpscan.com/vulnerability/c6bb12b1-6961-40bd-9110-edfa9ee41a18ExploitThird Party Advisory
FAQ
What is CVE-2021-24947?
CVE-2021-24947 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any a...
How severe is CVE-2021-24947?
CVE-2021-24947 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24947?
Check the references section above for vendor advisories and patch information. Affected products include: Thinkupthemes Responsive Vector Maps.