CVE detail
CVE-2021-24620 — CVE-2021-24620
Published 2021-09-13 · Modified 2026-06-17 · Vendor simple-e-commerce-shopping-cart_project · Product simple-e-commerce-shopping-cart · Source nvd
HIGH
severity
CVSS-derived band
0.0063
EPSS probability
exploitation probability, 30d
47.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check for the uploaded Downloadable Digital product file, allowing any file, such as PHP to be uploaded by an administrator. Furthermore, as there is no CSRF in place, attackers could also make a logged admin upload a malicious PHP file, which would lead to RCE
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References