ZeroHour

CVE-2021-24831

PoC
CVSS 3.1
7.5 high
EPSS
1%p66
Published
()
Modified
Description

All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete arbitrary tabs.

Vendors
rich-web
Products
tab
Ecosystems
WordPress
Weakness
CWE-862, CWE-425
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.