漏洞描述
WordPress Button Generator before 2.3.3 within the wow-company admin menu page allows arbitrary file inclusion with PHP extensions (as well as with data:// or http:// protocols), thus leading to cross-site request forgery and remote code execution.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
wpscan.comhttps://wpscan.com/vulnerability/a01844a0-0c43-4d96-b738-57fe5bfbd67a↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-25052↗plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/changeset/2641639/button-generation↗github.comhttps://github.com/ARPSyndicate/cvemon↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗