S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24370 Scanner

CVE-2021-24370 scanner - Arbitrary File Upload vulnerability in Fancy Product Designer plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24370
9.8
CVSS

The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Fancy Product Designer
AFFECTED< 4.6.9SAFE ✓≥ 4.6.9
Updated Aug 21, 2026View on NVD →
Detail

The Fancy Product Designer plugin for WordPress is a popular and powerful tool that allows users to create customized and interactive product designs, such as t-shirts, mugs, phone cases, and more, directly on their website. It is widely used by eCommerce businesses and online retailers as it enhances the customers’ shopping experience and increases their engagement with the brand. 

However, the plugin was recently found to have a critical vulnerability, CVE-2021-24370, which can be exploited by unauthenticated attackers to upload arbitrary files, leading to remote code execution. This means that cybercriminals can gain access to sensitive information, inject malicious code, and take control of the entire web application. The vulnerability affects all versions of Fancy Product Designer plugin before version 4.6.9.

When this vulnerability is exploited, it can cause severe consequences for website owners, such as data loss, website downtime, breach of confidential customer information, reputational damage, and financial losses. Attackers can use the vulnerability to install malware that can steal sensitive data or launch Distributed Denial of Service (DDoS) attacks against other websites. 

In conclusion, business owners and website administrators need to be aware of the CVE-2021-24370 vulnerability in the Fancy Product Designer plugin for WordPress and take the necessary steps to prevent it from being exploited. By using a reliable security platform like s4e.io, companies can stay on top of potential exploits and protect their digital assets from malicious actors. Don't take chances with your website's security, and act now to safeguard your business and protect your customers' data.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners are advised to take the following precautions:

  • Upgrade to the latest version of the Fancy Product Designer plugin (version 4.6.9 or higher)
  • Install a reliable security plugin that can detect and block any malicious activity
  • Regularly monitor the website for unusual traffic and suspicious activity
  • Set strict file permissions on the server
  • Follow best practices for web application security, such as using secure passwords and enabling SSL encryption.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.