Responsive Menu < 4.0.4 - CSRF to Arbitrary File Upload
CVE-2021-24161
8.8HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 5 April 2021
What is CVE-2021-24161?
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.
Affected Version(s)
Responsive Menu – Create Mobile-Friendly Menu 4.0.4
Responsive Menu Pro 4.0.4