Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24215
HistoryApr 12, 2021 - 2:00 p.m.

CVE-2021-24215 Controlled Admin Access < 1.5.2 - Improper Access Control & Privilege Escalation

2021-04-1214:00:48
CWE-284
WPScan
www.cve.org
2
controlled admin access
wordpress plugin
vulnerability
unauthorized access
website customization
cms settings

AI Score

9.6

Confidence

High

EPSS

0.275

Percentile

96.9%

An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.

CNA Affected

[
  {
    "product": "Controlled Admin Access",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "1.5.2",
        "status": "affected",
        "version": "1.5.2",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

9.6

Confidence

High

EPSS

0.275

Percentile

96.9%

Related for CVELIST:CVE-2021-24215