CVE-2021-24160 is a critical arbitrary file upload vulnerability affecting the Responsive Menu (free and Pro) WordPress plugins prior to version 4.0.4. This flaw allows authenticated subscribers to upload malicious PHP files within zip archives, which are then extracted to a publicly accessible directory. With a CVSS score of 8.8 (High), this vulnerability enables remote code execution, granting attackers full control over the compromised WordPress site. While no active exploitation, public exploit code, or significant community discussion has been observed, the high EPSS score and FAUCET Risk Score indicate a significant potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.4CPE matchmatch criteria | cpe:2.3:a:expresstech:responsive_menu:*:*:*:*:free:wordpress:*:* | ||
< 4.0.4CPE matchmatch criteria | cpe:2.3:a:expresstech:responsive_menu:*:*:*:*:pro:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.