CVE Feed

    Dashboard / CVE / CVE-2021-24220

    CVE-2021-24220

    Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0 register a REST API endpoint to compress images using the Kraken image optimization engine. By supplying a crafted request in combination with data inserted using the Option Update vulnerability, it was possible to use this endpoint to retrieve malicious code from a remote URL and overwrite an existing file on the site with it or create a new file.This includes executable PHP files that contain malicious code.

    Published:Apr 12, 2021
    Last Modified:Nov 21, 2024
    EPS:Apr 12, 2021
    EPSS Score:0.00435
    CVSS Score:9.1

    Affected Products

    Vendor
    Thrivethemes
    Product
    Focusblog
    Vendor
    Thrivethemes
    Product
    Ignition
    Vendor
    Thrivethemes
    Product
    Luxe
    Vendor
    Thrivethemes
    Product
    Minus
    Vendor
    Thrivethemes
    Product
    Performag
    Vendor
    Thrivethemes
    Product
    Pressive
    Vendor
    Thrivethemes
    Product
    Rise
    Vendor
    Thrivethemes
    Product
    Squared
    Vendor
    Thrivethemes
    Product
    Storied
    Vendor
    Thrivethemes
    Product
    Voice

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High