CVE-2021-24981
published 2021-12-21CVE-2021-24981: The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in…
PriorityP181high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
0.81%
52.3th percentile
The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wpwax | directorist | < 7.0.6.2 | 7.0.6.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g47h-745c-4p4f: The Directorist WordPress plugin before 7
ghsa_unreviewed·2021-12-22
CVE-2021-24981 [HIGH] CWE-352 GHSA-g47h-745c-4p4f: The Directorist WordPress plugin before 7
The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.
VulnCheck
wpwax directorist Cross-Site Request Forgery (CSRF)
vulncheck·2021·CVSS 7.5
CVE-2021-24981 [HIGH] wpwax directorist Cross-Site Request Forgery (CSRF)
wpwax directorist Cross-Site Request Forgery (CSRF)
The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.
Affected: wpwax directorist
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://wpscan.com/vulnerability/4c45df6d-b3f6-49e5-8b1f-edd32a12d71c/
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.sucuri.net/2021/11/fake-ransomware-infection-spooks-website-owners.htmlhttps://wpscan.com/vulnerability/4c45df6d-b3f6-49e5-8b1f-edd32a12d71chttps://blog.sucuri.net/2021/11/fake-ransomware-infection-spooks-website-owners.htmlhttps://wpscan.com/vulnerability/4c45df6d-b3f6-49e5-8b1f-edd32a12d71c
2021-12-21
Published
Exploited in the wild