PT-2021-15752 · WordPress · Wp Page Builder
Ramuel Gall
·
Published
2021-04-05
·
Updated
2022-07-29
·
CVE-2021-24207
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
WP Page Builder versions prior to 1.2.4
Description:
The issue allows subscriber-level users to edit and make changes to any and all posts and pages by default, unless user roles are specifically blocked from editing posts and pages.
Recommendations:
For versions prior to 1.2.4, update to version 1.2.4 or later to resolve the issue. As a temporary workaround, consider blocking subscriber-level users from editing posts and pages to minimize the risk of exploitation.
Exploit
Fix
Incorrect Authorization
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wp Page Builder