Responsive Menu 4.0.0 - 4.0.3 - Authenticated Arbitrary File Upload
CVE-2021-24160

8.8HIGH

Key Information:

Badges

πŸ‘Ύ Exploit Exists

Summary

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.

Affected Version(s)

Responsive Menu – Create Mobile-Friendly Menu 4.0.4

Responsive Menu Pro 4.0.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chloe Chamberland
.