ZeroHour

CVE-2021-24215

PoC
CVSS 3.1
9.8 critical
EPSS
10%p95
Published
()
Modified
Description

An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.

Vendors
wpruby
Products
controlled admin access
Ecosystems
WordPress
Weakness
CWE-284, CWE-425
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.