CVE Published: 14/05/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: WPScan |
Vendor: SayenThemes |
Product: Kaswara Modern VC Addons Status : PUBLISHED
CVE-2021-24284 Description
The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the \'uploadFontIcon\' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as PHP.