CVE-2021-24160
Published: Apr 5, 2021
Modified: Aug 3, 2024
Description
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.
| Vendor | Product | Versions |
|---|---|---|
ExpressTech | Responsive Menu – Create Mobile-Friendly Menu | affected 4.0.4 - < 4.0.4 |
ExpressTech | Responsive Menu Pro | affected 4.0.4 - < 4.0.4 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now