CyberRota Analysis
AI analysis pending.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Detected Signals
remote code execution code execution
GitHub PoC Links
External Security References
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2021-42362
Severity
HIGH
CVSS
8.8
EPSS
79.82%
WordPress
Original NVD Description
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.