CRITICAL

CVE-2021-24472

CVSS v3

9.8

CRITICAL

EPSS Score

89.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

Technical details

Published
8/2/2021

Frequently asked questions

What is CVE-2021-24472?

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

Is CVE-2021-24472 actively exploited?

Active exploitation of CVE-2021-24472 has not been confirmed. The EPSS score is 89.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-24472?

CVE-2021-24472 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-24472 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.