CVE-2021-24721
The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated "translator" users being able to inject PHP code into files ending with .php in web accessible locations.
- Affected products
- Loco Translate
- Loco Translate Project Loco Translate
- < 2.5.4
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.9% (59th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2021-11-08
CVE-2021-24721 at NVD
1 known exploit for CVE-2021-24721
Proof-of-concept code and exploit modules indexed by Sploitus