← back
CVE-2021-25094observed exploitationCWE-306

Tatsu < 3.3.12 - Unauthenticated RCE

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 83%
from disclosure to weapon0 days
Published on NVDApr 25
1st PoCJan 3
metasploitApr 25
VulnCheck+207d
exploitation probability
83%top 1% of all CVEs
observed exploitation
yesVulnCheck
9 public exploit(s)
The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin. Moreover, there is a race condition in the zip extraction process which makes the shell file live long enough on the filesystem to be callable by an attacker.
Affected products
Unknown · Tatsu
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.