{"cve":"CVE-2021-24370","epss":{"score":0.47371},"mitre":{"cpes":[],"created":"2021-06-21T00:00:00+00:00","description":"The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2021/24xxx/CVE-2021-24370.json","references":["https://lists.openwall.net/full-disclosure/2020/11/17/2","https://seclists.org/fulldisclosure/2020/Nov/30","https://wpscan.com/vulnerability/82c52461-1fdc-41e4-9f51-f9dd84962b38","https://www.secpod.com/blog/critical-zero-day-flaw-actively-exploited-in-wordpress-fancy-product-designer-plugin/","https://www.wordfence.com/blog/2021/06/critical-0-day-in-fancy-product-designer-under-active-attack/"],"title":"Fancy Product Designer < 4.6.9 - Unauthenticated Arbitrary File Upload and RCE","updated":"2024-08-03T19:28:23.807000+00:00","vendors":[],"weaknesses":["CWE-434"]},"nvd":{"cpes":["cpe:2.3:a:radykal:fancy_product_designer:*:*:*:*:*:wordpress:*:*"],"created":"2021-06-21T20:15:08.727000+00:00","description":"The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.","metrics":{"cvssV2_0":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2021/CVE-2021-24370.json","references":["https://lists.openwall.net/full-disclosure/2020/11/17/2","https://seclists.org/fulldisclosure/2020/Nov/30","https://wpscan.com/vulnerability/82c52461-1fdc-41e4-9f51-f9dd84962b38","https://www.secpod.com/blog/critical-zero-day-flaw-actively-exploited-in-wordpress-fancy-product-designer-plugin/","https://www.wordfence.com/blog/2021/06/critical-0-day-in-fancy-product-designer-under-active-attack/"],"title":null,"updated":"2026-06-17T03:39:54.880000+00:00","vendors":["radykal","radykal$PRODUCT$fancy_product_designer"],"weaknesses":["CWE-434"]},"opencve":{"changes":[],"cpes":{"data":["cpe:2.3:a:radykal:fancy_product_designer:*:*:*:*:*:wordpress:*:*"],"providers":["nvd"]},"created":{"data":"2021-06-21T00:00:00+00:00","provider":"mitre"},"description":{"data":"The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"provider":"nvd"},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"nvd"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.47371},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://lists.openwall.net/full-disclosure/2020/11/17/2","https://seclists.org/fulldisclosure/2020/Nov/30","https://wpscan.com/vulnerability/82c52461-1fdc-41e4-9f51-f9dd84962b38","https://www.secpod.com/blog/critical-zero-day-flaw-actively-exploited-in-wordpress-fancy-product-designer-plugin/","https://www.wordfence.com/blog/2021/06/critical-0-day-in-fancy-product-designer-under-active-attack/"],"providers":["mitre","nvd"]},"title":{"data":"Fancy Product Designer < 4.6.9 - Unauthenticated Arbitrary File Upload and RCE","provider":"mitre"},"updated":{"data":"2024-11-21T05:52:55.970000+00:00","provider":"nvd"},"vendors":{"data":["radykal","radykal$PRODUCT$fancy_product_designer"],"providers":["nvd"]},"weaknesses":{"data":["CWE-434"],"providers":["mitre","nvd"]}}}