Tatsu Wordpress Plugin RCE

cve CVE-2021-25094 2 sources, 2 claims · Watch

Metasploit exploit modules writes:
This module adds exploit for CVE-2021-25094 - unauthenticated remote code execution in Tatsu Wordpress plugin <= 3.3.11. Module uploads malicious zip with PHP payload that gets executed in second part of exploit. the claim

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBMilad karimi
receipt
Source
Exploit-DB
Its words
Milad karimi
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Milad karimi",
  "codes": "CVE-2021-25094",
  "date_added": "2025-04-18",
  "date_published": "2025-04-18",
  "date_updated": "2025-04-18",
  "description": "Tatsu 3.3.11 - Unauthenticated RCE",
  "file": "exploits/php/webapps/52260.py",
  "id": "52260",
  "platform": "php",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Platform
platform
not compared
Exploit-DBphp
receipt
Source
Exploit-DB
Its words
php
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Milad karimi",
  "codes": "CVE-2021-25094",
  "date_added": "2025-04-18",
  "date_published": "2025-04-18",
  "date_updated": "2025-04-18",
  "description": "Tatsu 3.3.11 - Unauthenticated RCE",
  "file": "exploits/php/webapps/52260.py",
  "id": "52260",
  "platform": "php",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Platform
platform
not compared
Metasploit exploit modulesPHP
receipt
Source
Metasploit exploit modules
Its words
PHP
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 19:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "php",
  "author": [
    "Vincent Michel",
    "msutovsky-r7"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module adds exploit for CVE-2021-25094 - unauthenticated remote code execution in Tatsu Wordpress plugin <= 3.3.11. Module uploads malicious zip with PHP payload that gets executed in second part of exploit.",
  "disclosure_date": "2022-04-25",
  "fullname": "exploit/multi/http/wp_tatsu_rce",
  "is_install_path": true,
  "mod_time": "2025-12-17 16:12:31 +0000",
  "name": "Tatsu Wordpress Plugin RCE",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "ioc-in-logs",
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/wp_tatsu_rce.rb",
  "platform": "PHP",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/wp_tatsu_rce",
  "references": [
    "CVE-2021-25094",
    "EDB-52260"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "PHP"
  ],
  "type": "exploit"
}
—
Rank
rank
Metasploit exploit modules600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 19:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "php",
  "author": [
    "Vincent Michel",
    "msutovsky-r7"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module adds exploit for CVE-2021-25094 - unauthenticated remote code execution in Tatsu Wordpress plugin <= 3.3.11. Module uploads malicious zip with PHP payload that gets executed in second part of exploit.",
  "disclosure_date": "2022-04-25",
  "fullname": "exploit/multi/http/wp_tatsu_rce",
  "is_install_path": true,
  "mod_time": "2025-12-17 16:12:31 +0000",
  "name": "Tatsu Wordpress Plugin RCE",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "ioc-in-logs",
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/wp_tatsu_rce.rb",
  "platform": "PHP",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/wp_tatsu_rce",
  "references": [
    "CVE-2021-25094",
    "EDB-52260"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "PHP"
  ],
  "type": "exploit"
}
—
Type
type
Exploit-DBwebapps
receipt
Source
Exploit-DB
Its words
webapps
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Milad karimi",
  "codes": "CVE-2021-25094",
  "date_added": "2025-04-18",
  "date_published": "2025-04-18",
  "date_updated": "2025-04-18",
  "description": "Tatsu 3.3.11 - Unauthenticated RCE",
  "file": "exploits/php/webapps/52260.py",
  "id": "52260",
  "platform": "php",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Verified
verified
Exploit-DBfalse
receipt
Source
Exploit-DB
Its words
0
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Milad karimi",
  "codes": "CVE-2021-25094",
  "date_added": "2025-04-18",
  "date_published": "2025-04-18",
  "date_updated": "2025-04-18",
  "description": "Tatsu 3.3.11 - Unauthenticated RCE",
  "file": "exploits/php/webapps/52260.py",
  "id": "52260",
  "platform": "php",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—

exploit

Tatsu Wordpress Plugin RCE
zetlyn/cve-metasploit · 2022-04-25
platform PHP rank 600 source
Tatsu 3.3.11 - Unauthenticated RCE
zetlyn/cve-exploitdb · 2025-04-18
author Milad karimi platform php type webapps verified false source