CVE detail
CVE-2021-24222 — CVE-2021-24222
Published 2021-04-12 · Modified 2026-06-17 · Vendor williamluis · Product wp-curriculo_vitae_free · Source nvd
CRITICAL
severity
CVSS-derived band
0.0243
EPSS probability
exploitation probability, 30d
83.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file extension restriction, leading to RCE.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References