High severity8.8NVD Advisory· Published Mar 31, 2022· Updated Jun 17, 2026
CVE-2021-34257
CVE-2021-34257
Description
Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wpanel/wpanel4-cmsPackagist | <= 4.3.1 | — |
Affected products
3- WPanel/WPaneldescription
Patches
Vulnerability mechanics
References
4- latestpcsolution.wordpress.com/2021/06/05/wpanel4-cms-authenticated-rce/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-vhgr-gfx3-fg37ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-34257ghsaADVISORY
- latestpcsolution.wordpress.com/2021/06/05/wpanel4-cms-authenticated-rceghsaWEB
News mentions
0No linked articles in our index yet.