The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T19:49:13.473Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24947

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-07T16:15:43.453

Modified: 2024-11-21T05:54:03.800

Link: CVE-2021-24947

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.