← Back

CVE-2021-24224

nvd nist
Published: Apr 12, 2021Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticated users, does not have any security in place to verify uploaded files, allowing low privilege users to upload arbitrary files, leading to RCE.

Affected (1)

Easy Form Builder By Bitware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.0

References (4)

Timeline

No history available yet.