← back
CVE-2021-24311observed exploitationCWE-434

External Media < 1.0.34 - Authenticated Arbitrary File Upload

25Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 1.8%
from disclosure to weapon
Published on NVDJun 1
VulnCheck+552d
exploitation probability
1.8%top 24% of all CVEs
observed exploitation
yesVulnCheck
The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any authenticated users.
Affected products
Unknown · External Media