Tatsu Wordpress Plugin RCE

zetlyn/cve-metasploit exploit cve CVE-2021-25094 known 2022-04-25

https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/wp_tatsu_rce.rb

Properties

platformPHP
receipt
Source
Metasploit exploit modules
Its words
PHP
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 22:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "php",
  "author": [
    "Vincent Michel",
    "msutovsky-r7"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module adds exploit for CVE-2021-25094 - unauthenticated remote code execution in Tatsu Wordpress plugin <= 3.3.11. Module uploads malicious zip with PHP payload that gets executed in second part of exploit.",
  "disclosure_date": "2022-04-25",
  "fullname": "exploit/multi/http/wp_tatsu_rce",
  "is_install_path": true,
  "mod_time": "2025-12-17 16:12:31 +0000",
  "name": "Tatsu Wordpress Plugin RCE",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "ioc-in-logs",
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/wp_tatsu_rce.rb",
  "platform": "PHP",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/wp_tatsu_rce",
  "references": [
    "CVE-2021-25094",
    "EDB-52260"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "PHP"
  ],
  "type": "exploit"
}
rank600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 22:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "php",
  "author": [
    "Vincent Michel",
    "msutovsky-r7"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module adds exploit for CVE-2021-25094 - unauthenticated remote code execution in Tatsu Wordpress plugin <= 3.3.11. Module uploads malicious zip with PHP payload that gets executed in second part of exploit.",
  "disclosure_date": "2022-04-25",
  "fullname": "exploit/multi/http/wp_tatsu_rce",
  "is_install_path": true,
  "mod_time": "2025-12-17 16:12:31 +0000",
  "name": "Tatsu Wordpress Plugin RCE",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "ioc-in-logs",
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/wp_tatsu_rce.rb",
  "platform": "PHP",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/wp_tatsu_rce",
  "references": [
    "CVE-2021-25094",
    "EDB-52260"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "PHP"
  ],
  "type": "exploit"
}

Text

This module adds exploit for CVE-2021-25094 - unauthenticated remote code execution in Tatsu Wordpress plugin <= 3.3.11. Module uploads malicious zip with PHP payload that gets executed in second part of exploit.