peter bassill · operator
$ cve CVE-2021-4436 JSON

CVE-2021-4436

9.8
CRITICAL · CVSS 3.1 · EPSS 6.6% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers such as Apache.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.65% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploitnone known
Published2024-02-05
Last modified2026-06-17

Affected (1)

VendorProduct
wp3dprinting3dprint lite

References

→ the Explorer  ·  watch your stack  ·  NVD