CVE-2021-45806 describes a critical vulnerability in jpress v4.2.0, where an authenticated attacker can inject malicious code through the administrative panel's template modification function. This allows for high impact to confidentiality, integrity, and availability with low attack complexity, as reflected by its CVSS score of 8.8 (High). Despite its severity, there is currently no evidence of active exploitation, publicly available exploit code in common frameworks like Metasploit or Nuclei, nor significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.0CPE matchmatch criteria | cpe:2.3:a:jpress:jpress:4.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.