Remote Code Execution in JPress 4.2.0 Admin Panel
CVE-2021-46116
7.2HIGH
What is CVE-2021-46116?
The JPress 4.2.0 version is susceptible to a vulnerability that allows remote code execution through the admin panel. Specifically, the flaw exists in the TemplateController's install function, enabling attackers to install templates that contain malicious code. This vulnerability could potentially lead to significant security risks if exploited, as it allows unauthorized commands to be executed on the server.