Description
The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers such as Apache.
Published: 2024-02-05
Score: 9.8 Critical
EPSS: 76.9% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:wp3dprinting:3dprint_lite:-:*:*:*:*:wordpress:*:*
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Wp3dprinting 3dprint Lite
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-01-09T21:05:31.460Z

Reserved: 2024-02-05T08:57:43.929Z

Link: CVE-2021-4436

cve-icon Vulnrichment

Updated: 2024-08-03T17:30:07.527Z

cve-icon NVD

Status : Modified

Published: 2024-02-05T09:15:43.013

Modified: 2024-11-21T06:37:43.550

Link: CVE-2021-4436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses