← volver
CVE-2021-24215CWE-284

Controlled Admin Access < 1.5.2 - Improper Access Control & Privilege Escalation

18Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendepss 9.7%
probabilidad de explotación
9.7%top 5% de las CVE
explotación observada
noninguna fuente lo reporta
An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.