CVE detail
CVE-2021-4436 — CVE-2021-4436
Published 2024-02-05 · Modified 2026-06-17 · Vendor wp3dprinting · Product 3dprint_lite · Source nvd
CRITICAL
severity
CVSS-derived band
0.0665
EPSS probability
exploitation probability, 30d
93.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers such as Apache.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References