CVE-2021-25094 | Tatsu Plugin up to 3.3.11 on WordPress ZIP File add_custom_font unrestricted upload (EDB-52260)
A vulnerability classified as problematic has been found in Tatsu Plugin up to 3.3.11 on WordPress. Affected is the function add_custom_font of the component ZIP File Handler. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2021-25094. The attack needs to be initiated within the local network. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.