CVE-2021-25094
Tatsu < 3.3.12 - Unauthenticated RCE
- Published
- Apr 25, 2022
- Updated
- Apr 21, 2025
- Assigning CNA
- WPScan
- Evidence observed
- Apr 18, 2025
Tatsu < 3.3.12 - Unauthenticated RCE
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin. Moreover, there is a race condition in the zip extraction process which makes the shell file live long enough on the filesystem to be callable by an attacker.
Proof-of-concept exploit for unauthenticated remote code execution in Tatsu Builder WordPress plugin (CVE-2021-25094). Supports multiple shell techniques, proxy, and compression levels.
This script exploits a vulnerability (CVE-2021-25094) in the TypeHub WordPress plugin.
GILANG - Exploiter for CVE-2021-25094
Tatsu Plugin ZIP File add_custom_font unrestricted upload
Milad karimi · php · Apr 18, 2025
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.