{ "schema_version": "1.4.0", "id": "GHSA-rrx2-h7gv-6jx5", "modified": "2022-05-24T19:01:31Z", "published": "2022-05-24T19:01:31Z", "aliases": [ "CVE-2021-24253" ], "details": "The Classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds a listing, only checking the content-type in the request. This allows any authenticated user to upload arbitrary PHP files via the Add Listing feature of the plugin, leading to RCE.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-24253" }, { "type": "WEB", "url": "https://github.com/jinhuang1102/CVE-ID-Reports/blob/master/classyfrieds.md" }, { "type": "WEB", "url": "https://wpscan.com/vulnerability/ee42c233-0ff6-4b27-a5ec-ad3246bef079" } ], "database_specific": { "cwe_ids": [ "CWE-434" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-05-06T13:15:00Z" } }