CVSS v3
8.8
HIGH
EPSS Score
62.9%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.
Active exploitation of CVE-2021-24160 has not been confirmed. The EPSS score is 62.9%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2021-24160 has a CVSS v3 base score of 8.8 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).