CVE-2021-42362

WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.


We have discovered 23,846 live websites that are affected by CVE-2021-42362.

Test my site




Affected Software

Product  WordPress Popular Posts
Category Wordpress Plugins
Vulnerable Domains23,846 live websites (26.49% of WordPress Popular Posts install base)
Vulnerable Versions
  • from 0 through 5.3.2
Vulnerable Versions Count78 versions ( 60.94% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Nov 17, 2021
  • Updated - Sep 16, 2024

Credits

  • Original Researcher: Jerome Bruandet, NinTechNet Exploit Author: Simone Cristofaro (finder)

CVE-2021-42362 usage by Country

United States4,148 websites



Japan13,039 websites
Russia955 websites
Germany758 websites
France484 websites
Poland456 websites
Vietnam324 websites
Brazil230 websites
GB181 websites

CVE-2021-42362 usage by TLD

.com12,585 websites
.net1,939 websites
.jp1,891 websites
.ru1,016 websites
.org699 websites
.info512 websites
.co.jp489 websites
.pl327 websites
.de300 websites
.com.br244 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-42362

Top websites that are affected by CVE-2021-42362. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.uk United States*,***
**********.com United States*,***
***************.com United States**,***
*******************.com Japan**,***
********.tokyo Japan**,***
*****.com United States**,***
******.com United States**,***
***************.com United States**,***
**************.com United States**,***
****.com United States**,***
See full domain list

FAQ

CVE-2021-42362 is Unrestricted Upload of File with Dangerous Type in WordPress Popular Posts
A total of 23,846 websites have been identified as vulnerable to CVE-2021-42362, discovered through global website indexing conducted by WebTechSurvey.
WordPress Popular Posts is susceptible to CVE-2021-42362 vulnerability.
WordPress Popular Posts versions before, and including, 5.3.2 are vulnerable to CVE-2021-42362.