ZeroHour

CVE-2021-24717

PoC
CVSS 3.1
8.8 high
EPSS
1%p70
Published
()
Modified
Description

The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

Vendors
automatorwp
Products
automatorwp
Ecosystems
WordPress
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.