Arbitrary file upload in Fancy Product Designer - CVE-2021-24370
Published: June 2, 2021 / Updated: October 13, 2021
Fancy Product Designer
radykal
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload in "wp-admin" or "wp-content/plugins/fancy-product-designer/inc". A remote attacker can upload a malicious file and execute it on the server.
Note, the vulnerability is being actively exploited in the wild.