vulnerability

WordPress Plugin: powerpress: CVE-2021-24123: Unrestricted Upload of File with Dangerous Type

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Oct 11, 2020
Added
May 15, 2025
Modified
May 15, 2025

Description

Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.7, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.

Solution

powerpress-plugin-cve-2021-24123
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.