CVE Database
/

CVE-2021-24160

Back to search

CVE-2021-24160

Published: Apr 5, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.

VendorProductVersions

ExpressTech

Responsive Menu – Create Mobile-Friendly Menu

affected
4.0.4 - < 4.0.4

ExpressTech

Responsive Menu Pro

affected
4.0.4 - < 4.0.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now