Vulnerability Details CVE-2021-25003
The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE
Exploit prediction scoring system (EPSS) score
EPSS Score 0.919
EPSS Ranking 99.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-25003
-
cpe:2.3:a:wptaskforce:wpcargo_track_&_trace:*