ZeroHour

CVE-2021-24872

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p61
Published
()
Modified
Description

The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validating the permissions. Eg. contributors can access admin posts metadata.

Vendors
get custom field values project
Products
get custom field values
Ecosystems
WordPress
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.