PT-2021-15752 · WordPress · Wp Page Builder

Ramuel Gall

·

Published

2021-04-05

·

Updated

2022-07-29

·

CVE-2021-24207

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: WP Page Builder versions prior to 1.2.4
Description: The issue allows subscriber-level users to edit and make changes to any and all posts and pages by default, unless user roles are specifically blocked from editing posts and pages.
Recommendations: For versions prior to 1.2.4, update to version 1.2.4 or later to resolve the issue. As a temporary workaround, consider blocking subscriber-level users from editing posts and pages to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24207

Affected Products

Wp Page Builder