CVE-2021-34627 is a low-severity vulnerability in the WP Upload Restriction WordPress plugin, affecting versions 2.2.3 and prior. It allows authenticated low-level users to view custom file extensions configured by administrators, potentially exposing sensitive configuration details. The CVSS score is 4.3 (Medium), indicating a network-based attack with low complexity and no integrity or availability impact, only a limited confidentiality impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.3CPE matchmatch criteria | cpe:2.3:a:wp-upload-restriction_project:wp-upload-restriction:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.