The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.
References
Link | Resource |
---|---|
https://codecanyon.net/item/business-hours-pro-wordpress-plugin/9414879 | Product Third Party Advisory |
https://wpscan.com/vulnerability/10528cb2-12a1-43f7-9b7d-d75d18fdf5bb | Third Party Advisory |
https://codecanyon.net/item/business-hours-pro-wordpress-plugin/9414879 | Product Third Party Advisory |
https://wpscan.com/vulnerability/10528cb2-12a1-43f7-9b7d-d75d18fdf5bb | Third Party Advisory |
Configurations
History
21 Nov 2024, 05:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://codecanyon.net/item/business-hours-pro-wordpress-plugin/9414879 - Product, Third Party Advisory | |
References | () https://wpscan.com/vulnerability/10528cb2-12a1-43f7-9b7d-d75d18fdf5bb - Third Party Advisory |
Information
Published : 2021-04-22 21:15
Updated : 2024-11-21 05:52
NVD link : CVE-2021-24240
Mitre link : CVE-2021-24240
CVE.ORG link : CVE-2021-24240
JSON object : View
Products Affected
aivahthemes
- business_hours_pro
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type