AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-24123

HIGH · CVSS 7.2 EPSS 1.65%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-03-18 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-24123
Severity
HIGH
CVSS
7.2
EPSS
1.65%
WordPress

Original NVD Description

Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.