CVE-2021-25094
By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 83.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin. Moreover, there is a race condition in the zip extraction process which makes the shell file live long enough on the filesystem to be callable by an attacker.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 83.35% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- brandexponents/tatsu
- Source
- contact@wpscan.com
References
- http://packetstormsecurity.com/files/167190/WordPress-Tatsu-Builder-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://darkpills.com/wordpress-tatsu-builder-preauth-rce-cve-2021-25094/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/fb0097a0-5d7b-4e5b-97de-aacafa8fffcdExploit, Third Party Advisory
- http://packetstormsecurity.com/files/167190/WordPress-Tatsu-Builder-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://darkpills.com/wordpress-tatsu-builder-preauth-rce-cve-2021-25094/Exploit, Third Party Advisory
- https://packetstorm.news/files/id/190566/
- https://wpscan.com/vulnerability/fb0097a0-5d7b-4e5b-97de-aacafa8fffcdExploit, Third Party Advisory
- https://www.exploit-db.com/exploits/52260
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.