CVE Feed

    Dashboard / CVE / CVE-2021-25004

    CVE-2021-25004

    The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL and a password than an administrator can see in the plugin settings page.

    Published:Feb 7, 2022
    Last Modified:Nov 21, 2024
    EPS:Feb 7, 2022
    EPSS Score:0.00639
    CVSS Score:4.9

    Affected Products

    Vendor
    Seur Oficial Project
    Product
    Seur Oficial

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High