Lucene search

K
cveWordfenceCVE-2021-4374
HistoryJun 07, 2023 - 2:15 a.m.

CVE-2021-4374

2023-06-0702:15:15
CWE-862
Wordfence
web.nvd.nist.gov
20
wordpress
automatic plugin
cve-2021-4374
vulnerability
arbitrary options updates
unauthenticated attackers
compromise
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.004

Percentile

73.2%

The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. This makes it possible for unauthenticated attackers to arbitrarily update the settings of a vulnerable site and ultimately compromise the entire site.

Affected configurations

Nvd
Vulners
Node
valvepresswordpress_automatic_pluginRange3.53.2wordpress
VendorProductVersionCPE
valvepresswordpress_automatic_plugin*cpe:2.3:a:valvepress:wordpress_automatic_plugin:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "ValvePress",
    "product": "WordPress Automatic Plugin",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThan": "3.53.3",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.004

Percentile

73.2%

Related for CVE-2021-4374