CVE Database
/

CVE-2021-24224

Back to search

CVE-2021-24224

Published: Apr 12, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticated users, does not have any security in place to verify uploaded files, allowing low privilege users to upload arbitrary files, leading to RCE.

VendorProductVersions

Unknown

Easy Form Builder

affected
1.0 - <= 1.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now