← Back to browse · API

CVE-2021-42362

Severity
HIGH
CVSS
8.8
EPSS
0.79823
Risk score
63.14
CISA KEV
No
PoC
No
Published
2021-11-17
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-29333, GHSA-P9WV-PHC4-8HQF
Products
Hector Cabrera:WordPress Popular Posts 0.0 ≤5.3.2
Sources
euvd EUVD-2021-29333

Description

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.

References