CVE-2021-24430

The Speed Booster Pack ? PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_query_strings settings before outputting them in a PHP file, which could lead to RCE
Configurations

Configuration 1 (hide)

cpe:2.3:a:optimocha:speed_booster_pack:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 05:53

Type Values Removed Values Added
References () https://m0ze.ru/vulnerability/%5B2021-05-10%5D-%5BWordPress%5D-%5BCWE-94%5D-Speed-Booster-Pack-WordPress-Plugin-v4.2.0-beta.txt - () https://m0ze.ru/vulnerability/%5B2021-05-10%5D-%5BWordPress%5D-%5BCWE-94%5D-Speed-Booster-Pack-WordPress-Plugin-v4.2.0-beta.txt -
References () https://wpscan.com/vulnerability/945d6d2e-fa25-42c0-a7b4-b1794732a0df - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/945d6d2e-fa25-42c0-a7b4-b1794732a0df - Exploit, Third Party Advisory

07 Nov 2023, 03:31

Type Values Removed Values Added
Summary The Speed Booster Pack âš¡ PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_query_strings settings before outputting them in a PHP file, which could lead to RCE The Speed Booster Pack ? PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_query_strings settings before outputting them in a PHP file, which could lead to RCE
References
  • {'url': 'https://m0ze.ru/vulnerability/[2021-05-10]-[WordPress]-[CWE-94]-Speed-Booster-Pack-WordPress-Plugin-v4.2.0-beta.txt', 'name': 'https://m0ze.ru/vulnerability/[2021-05-10]-[WordPress]-[CWE-94]-Speed-Booster-Pack-WordPress-Plugin-v4.2.0-beta.txt', 'tags': ['Exploit', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://m0ze.ru/vulnerability/%5B2021-05-10%5D-%5BWordPress%5D-%5BCWE-94%5D-Speed-Booster-Pack-WordPress-Plugin-v4.2.0-beta.txt -

Information

Published : 2021-08-02 11:15

Updated : 2024-11-21 05:53


NVD link : CVE-2021-24430

Mitre link : CVE-2021-24430

CVE.ORG link : CVE-2021-24430


JSON object : View

Products Affected

optimocha

  • speed_booster_pack
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')