vendor:
Tatsu wordpress plugin
by:
Milad Karimi (Ex3ptionaL)
6.1
CVSS
HIGH
Unauthenticated Remote Code Execution
CWE
Product Name: Tatsu wordpress plugin
Affected Version From: 3.3
Affected Version To: 40605
Patch Exists: YES
Related CWE: CVE-2021-25094
CPE: a:tatsu:wordpress_plugin:3.3.11
Platforms Tested: WordPress
2025
Tatsu 3.3.11 – Unauthenticated Remote Code Execution
The Tatsu wordpress plugin version 3.3.11 and below is vulnerable to unauthenticated remote code execution. An attacker can exploit this vulnerability to execute arbitrary code on the target system. This vulnerability is identified as CVE-2021-25094.
Mitigation:
Update to the latest version of the Tatsu wordpress plugin (3.3.12 or higher) to mitigate this vulnerability.