Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ValvePress | WordPress Automatic Plugin | * ~ 3.53.3 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress Automatic Plugin (versions 3.53.2 and below) contains a critical vulnerability that allows unauthenticated users to change arbitrary WordPress options through the process_form.php script. The vulnerable script uses update_option() on all POST parameters without authentication or capability checks, allowing attackers to create administrator accounts or modify critical settings. The vulnerability can be exploited even if the plugin is deactivated as it's a standalone script. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-4374.yaml | POC Details |
| 2 | None | https://github.com/Pranjal6955/CVE-2021-4374-Testing-Package | POC Details |
No public POC found.
Login to generate AI POCNo comments yet