漏洞描述
WordPress Fancy Product Designer plugin before 4.6.9 is susceptible to an arbitrary file upload. An attacker can upload malicious files and execute code on the server, modify data, and/or gain full control over a compromised system without authentication.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.wordfence.comhttps://www.wordfence.com/blog/2021/06/critical-0-day-in-fancy-product-designer-under-active-attack/↗wpscan.comhttps://wpscan.com/vulnerability/82c52461-1fdc-41e4-9f51-f9dd84962b38↗seclists.orghttps://seclists.org/fulldisclosure/2020/Nov/30↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-24370↗