CVSS v3
8.8
HIGH
EPSS Score
42.4%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
Active exploitation of CVE-2021-25052 has not been confirmed. The EPSS score is 42.4%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2021-25052 has a CVSS v3 base score of 8.8 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).