peter bassill · operator
$ cve CVE-2021-24236 JSON

CVE-2021-24236

9.8
CRITICAL · CVSS 3.1 · EPSS 7.3% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.28% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploitnone known
Published2021-05-06
Last modified2026-06-17

Affected (1)

VendorProduct
imagements projectimagements

References

→ the Explorer  ·  watch your stack  ·  NVD