← Vulnerability feed

Vulnerability record · CVE-2021-42362 · published 17 November 2021

CVE-2021-42362: WordPress Popular Posts plugin unrestricted file upload allows RCE

WWordpress Popular Posts Project · Wordpress Popular Posts

The WordPress Popular Posts plugin fails to properly validate uploaded file types in src/Image.php, allowing files with dangerous extensions to be stored on the server. This affects versions up to and including 5.3.2 and matters because uploaded files can be executed, turning a plugin flaw into full remote code execution.

8.8 CVSS 3.1 High EPSS 80% · top 0.4% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 6.5
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw yields remote code execution with only low-privileged authenticated access, public exploit code exists, and EPSS is very high, though it is not in KEV and requires an account.

What it is

The WordPress Popular Posts plugin fails to properly validate uploaded file types in src/Image.php, allowing files with dangerous extensions to be stored on the server. This affects versions up to and including 5.3.2 and matters because uploaded files can be executed, turning a plugin flaw into full remote code execution.

Impact

An attacker with contributor-level access or above can upload a malicious file and execute it on the server, gaining code execution in the context of the web server. That typically means full compromise of the WordPress site and any data or credentials reachable from it.

Attack surface

The flaw is reached over the network through the plugin's image upload handling; the CVSS vector shows PR:L, so a low-privileged authenticated account (contributor or higher) is required, and no user interaction is needed.

Exploitation

Public exploit code is referenced (Packet Storm and NinTechNet posts tagged Exploit), and EPSS is very high at roughly 0.798 with a 0.996 percentile, indicating active interest. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded here.

What to do

  • Update the WordPress Popular Posts plugin to a version later than 5.3.2, which contains the fix in src/Image.php.
  • If immediate patching is not possible, disable or remove the plugin until it can be updated.
  • Restrict contributor and author accounts to trusted users and review role assignments for unnecessary upload privileges.
  • Harden upload handling at the web server level by blocking execution of script files in the WordPress uploads directory.
  • Monitor plugin and WordPress core updates as part of a routine patch cycle.

Detection

  • Review the WordPress uploads directory for unexpected script files (for example .php, .phtml, .php5) and alert on their creation.
  • Audit web server logs for requests to uploaded files that return 200 and originate from non-admin users or unusual user agents.
  • Monitor plugin file changes and compare src/Image.php against the patched version to confirm the fix is applied.
  • Track contributor-level account activity for uploads outside normal image types or unusual file sizes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-42362 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2022-43468Wordpress popular posts project wordpress popular posts vulnerabilityExternal initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerab…EPSS 0.89%5.4CVE-2023-45607Wordpress popular posts project wordpress popular posts cross-site scripting vulnerabilityAuth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Hector Cabrera WordPress Popular Posts plugin <= 6.3.2 versions.EPSS 0.34%5.4CVE-2021-36872Wordpress popular posts project wordpress popular posts cross-site scripting vulnerabilityAuthenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2]…EPSS 0.59%5.4CVE-2021-20746Wordpress popular posts project wordpress popular posts cross-site scripting vulnerabilityCross-site scripting vulnerability in WordPress Popular Posts 5.3.2 and earlier allows a remote authenticated attacker to inject an arbitrary script …EPSS 1.4%10.0CVE-2026-56291Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCEThe Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing exe…KEVEPSS 15%analysed10.0CVE-2026-48939iCagenda Joomla extension unrestricted file upload leads to PHP RCEThe iCagenda extension for Joomla fails to restrict file types in its file attachment feature, allowing arbitrary file uploads that result in PHP cod…KEVEPSS 20%analysed10.0CVE-2026-56290Joomla Page Builder CK unauthenticated file upload leads to RCEThe Joomla Page Builder CK extension before 3.6.0 allows unauthenticated arbitrary file uploads, letting an attacker place executable files on the se…KEVEPSS 31%analysed10.0CVE-2026-48908SP Page Builder for Joomla unauthenticated arbitrary file upload RCESP Page Builder for Joomla permits unauthenticated users to upload arbitrary files, which can lead to upload and execution of PHP code. The flaw is a…KEVEPSS 89%analysed

Source: NIST National Vulnerability Database (record CVE-2021-42362), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.