CVE-2021-25094 is a critical unauthenticated Remote Code Execution (RCE) vulnerability affecting the Tatsu WordPress plugin versions prior to 3.3.12. Attackers can exploit a flaw in the add_custom_font action to upload a malicious ZIP file containing a PHP shell, bypassing extension controls and leveraging a race condition during extraction. This vulnerability carries a CVSS score of 8.1 (HIGH), indicating high impact on confidentiality, integrity, and availability, with low attack complexity and no user interaction required. The vulnerability is actively exploited, with multiple public exploit modules available (Metasploit, Nuclei, ExploitDB), significant community discussion, and media coverage highlighting widespread attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.12CPE matchmatch criteria | cpe:2.3:a:brandexponents:tatsu:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.