← back
CVE-2021-24739CWE-639

Logo Carousel < 3.4.2 - Unauthorised Private Post Access

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.0%
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature