CVE Feed

    Dashboard / CVE / CVE-2021-24375

    CVE-2021-24375

    Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_quick_view AJAX handlers of the Motor WordPress theme before 3.1.0 allows an unauthenticated attacker access to arbitrary files in the server file system, and to execute arbitrary php scripts found on the server file system. We found no vulnerability for uploading files with this theme, so any scripts to be executed must already be on the server file system.

    Published:Jul 6, 2021
    Last Modified:Nov 21, 2024
    EPS:Jul 6, 2021
    EPSS Score:0.02782
    CVSS Score:9.8

    Affected Products

    Vendor
    Stockware
    Product
    Motor

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High