Vulnerability record · CVE-2021-42362 · published 17 November 2021
CVE-2021-42362: WordPress Popular Posts plugin unrestricted file upload allows RCE
WWordpress Popular Posts Project · Wordpress Popular Posts
The WordPress Popular Posts plugin fails to properly validate uploaded file types in src/Image.php, allowing files with dangerous extensions to be stored on the server. This affects versions up to and including 5.3.2 and matters because uploaded files can be executed, turning a plugin flaw into full remote code execution.
Description
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw yields remote code execution with only low-privileged authenticated access, public exploit code exists, and EPSS is very high, though it is not in KEV and requires an account.
What it is
The WordPress Popular Posts plugin fails to properly validate uploaded file types in src/Image.php, allowing files with dangerous extensions to be stored on the server. This affects versions up to and including 5.3.2 and matters because uploaded files can be executed, turning a plugin flaw into full remote code execution.
Impact
An attacker with contributor-level access or above can upload a malicious file and execute it on the server, gaining code execution in the context of the web server. That typically means full compromise of the WordPress site and any data or credentials reachable from it.
Attack surface
The flaw is reached over the network through the plugin's image upload handling; the CVSS vector shows PR:L, so a low-privileged authenticated account (contributor or higher) is required, and no user interaction is needed.
Exploitation
Public exploit code is referenced (Packet Storm and NinTechNet posts tagged Exploit), and EPSS is very high at roughly 0.798 with a 0.996 percentile, indicating active interest. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded here.
What to do
- Update the WordPress Popular Posts plugin to a version later than 5.3.2, which contains the fix in src/Image.php.
- If immediate patching is not possible, disable or remove the plugin until it can be updated.
- Restrict contributor and author accounts to trusted users and review role assignments for unnecessary upload privileges.
- Harden upload handling at the web server level by blocking execution of script files in the WordPress uploads directory.
- Monitor plugin and WordPress core updates as part of a routine patch cycle.
Detection
- Review the WordPress uploads directory for unexpected script files (for example .php, .phtml, .php5) and alert on their creation.
- Audit web server logs for requests to uploaded files that return 200 and originate from non-admin users or unusual user agents.
- Monitor plugin file changes and compare src/Image.php against the patched version to confirm the fix is applied.
- Track contributor-level account activity for uploads outside normal image types or unusual file sizes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-42362 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-42362), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.