LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2021-47933

Published
CVSS9.8
Severitycritical
WeaknessCWE-306
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP files with arbitrary names to the config_file endpoint to achieve remote code execution on the server.

References

← Back to the CVE Tracker

Our coverage of CVE-2021-47933

No stories yet. This page updates automatically when we publish reporting that references CVE-2021-47933.