CVE-2021-4330: Envato Elements <= 2.0.10 & Template Kit <= 1.0.13 - Authenticated (Contributor+) Arbitrary File Upload
The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads due to insufficient validation of file type upon extracting uploaded Zip files in the installFreeTemplateKit and uploadTemplateKitZipFile functions. This makes it possible for attackers with contributor-lever permissions and above to upload arbitrary files and potentially gain remote code execution in versions up to and including 1.0.13 of Template Kit – Import and versions up to and including 2.0.10 of Envato Elements & Download.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-4330.
What is the severity of CVE-2021-4330?
The severity of CVE-2021-4330 is high (8.8).
Which software versions are affected by CVE-2021-4330?
Envato Elements version up to 2.0.10 and Template Kit - Import version up to 1.0.13 are affected.
How does CVE-2021-4330 work?
CVE-2021-4330 allows an attacker to upload arbitrary files by exploiting insufficient validation of file type when extracting uploaded Zip files in certain functions.
Are there any references for CVE-2021-4330?
Yes, you can find references for CVE-2021-4330 [here](https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2617529%40envato-elements&new=2617529%40envato-elements&sfp_email=&sfph_mail=) and [here](https://www.wordfence.com/threat-intel/vulnerabilities/id/68fe17e2-d5ab-4ebd-a5c6-d65cea327abd).