CVE-2021-36888
9.8
CRITICAL · CVSS 3.1 · EPSS 6.7% (pctl 94)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.69% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-284 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-12-15 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| blocksera | image hover effects |
References
- https://patchstack.com/database/vulnerability/image-hover-effects-ultimate/wordpress-image-hover-effects-ultimate-plugin-9-6-1-unauthenticated-arbitrary-options-update-leading-to-full-website-compromise
- https://wordpress.org/plugins/image-hover-effects-ultimate/#developers
- https://patchstack.com/database/vulnerability/image-hover-effects-ultimate/wordpress-image-hover-effects-ultimate-plugin-9-6-1-unauthenticated-arbitrary-options-update-leading-to-full-website-compromise
- https://wordpress.org/plugins/image-hover-effects-ultimate/#developers
→ the Explorer · watch your stack · NVD