peter bassill · operator
$ cve CVE-2021-24472 JSON

CVE-2021-24472

9.8
CRITICAL · CVSS 3.1 · EPSS 56.6% (pctl 99)

Patch early

EPSS 56.6% — above the 10% action threshold.

Description

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS56.61% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-918
On CISA KEVno
Public exploitnone known
Published2021-08-02
Last modified2026-06-17

Affected (2)

VendorProduct
qantumthemeskentharadio
qantumthemesonair2

References

→ the Explorer  ·  watch your stack  ·  NVD