← back
CVE-2021-24240observed exploitationCWE-434

Business Hours Pro <= 5.5.0 - Unauthenticated Arbitrary File Upload to RCE

25Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 3.0%
from disclosure to weapon
Published on NVDApr 22
VulnCheckApr 2
exploitation probability
3.0%top 14% of all CVEs
observed exploitation
yesVulnCheck
The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.