Lucene search

K
cveWordfenceCVE-2021-4362
HistoryJun 07, 2023 - 2:15 a.m.

CVE-2021-4362

2023-06-0702:15:14
CWE-862
Wordfence
web.nvd.nist.gov
15
kiwi social share
wordpress
vulnerability
authorization bypass
capability check
ajax action
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.003

Percentile

70.2%

The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in version 2.1.0. This makes it possible for unauthenticated attackers to read and modify arbitrary options on a WordPress site that can be used for complete site takeover. This was a previously fixed vulnerability that was reintroduced in this version.

Affected configurations

Nvd
Vulners
Node
wpkubekiwi_social_shareMatch2.1.0wordpress
VendorProductVersionCPE
wpkubekiwi_social_share2.1.0cpe:2.3:a:wpkube:kiwi_social_share:2.1.0:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "wpkube",
    "product": "Social Sharing Plugin – Kiwi",
    "versions": [
      {
        "version": "2.1.0",
        "status": "affected",
        "lessThanOrEqual": "2.1.2",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.003

Percentile

70.2%

Related for CVE-2021-4362