CVE-2021-24240observed exploitationCWE-434

CVE-2021-24240: vulnerability in Business Hours Pro

Business Hours Pro <= 5.5.0 - Unauthenticated Arbitrary File Upload to RCE

Published · Updated

25Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 3.0%
from disclosure to weapon
Published on NVDApr 22
VulnCheckApr 2
exploitation probability
3.0%top 13% of all CVEs
observed exploitation
yesVulnCheck
The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.