SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-25094

By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin.

HIGH 8.1EPSS 83.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 83.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin. Moreover, there is a race condition in the zip extraction process which makes the shell file live long enough on the filesystem to be callable by an attacker.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
83.35% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-306
Affected
brandexponents/tatsu
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.