High severity8.8NVD Advisory· Published May 14, 2021· Updated Jun 17, 2026
CVE-2021-24192
CVE-2021-24192
Description
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <2.9
- wp-buy/Tree Sitemap (Pages, Posts & Categories list)v5Range: 2.9
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/74889e29-5349-43d1-baf5-1622493be90cnvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.