Vulnerabilities > CVE-2021-24981 - Unspecified vulnerability in Wpwax Directorist
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.
Vulnerable Configurations
References
- https://blog.sucuri.net/2021/11/fake-ransomware-infection-spooks-website-owners.html
- https://blog.sucuri.net/2021/11/fake-ransomware-infection-spooks-website-owners.html
- https://wpscan.com/vulnerability/4c45df6d-b3f6-49e5-8b1f-edd32a12d71c
- https://wpscan.com/vulnerability/4c45df6d-b3f6-49e5-8b1f-edd32a12d71c