CVE-2021-4436 is a critical arbitrary file upload vulnerability affecting the 3DPrint Lite WordPress plugin prior to version 1.9.1.5. This flaw allows unauthenticated attackers to upload arbitrary files to the web server due to a lack of authorization and file validation in the p3dlite_handle_upload AJAX action. With a CVSS score of 9.8 (Critical), it presents a severe risk of complete compromise of confidentiality, integrity, and availability. While a .htaccess file may prevent direct web access on Apache, the vulnerability itself remains critical. There is no evidence of active exploitation, Metasploit modules, or ExploitDB entries, though Nuclei templates exist. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.1.5CPE matchmatch criteria | cpe:2.3:a:wp3dprinting:3dprint_lite:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.