CVE-2021-24842
PoC —CVSS 3.1
5.4 medium
EPSS
<1%p51
Published
()
Modified
Description
The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.
- Vendors
- bulk datetime change project
- Products
- bulk datetime change
- Ecosystems
- WordPress
- Weakness
- CWE-862, CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.