PT-2021-16244 · WordPress · Logo Slider/Showcase

Apple502J

·

Published

2021-11-01

·

Updated

2021-11-30

·

CVE-2021-24742

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Logo Slider and Showcase WordPress plugin versions prior to 1.3.37
Description: The issue allows Editor users to update the plugin's settings via the "rtWLSSettings" AJAX action because it uses a nonce for authorization instead of a capability check.
Recommendations: For versions prior to 1.3.37, update to version 1.3.37 or later to resolve the issue. As a temporary workaround, consider restricting access to the "rtWLSSettings" AJAX action to prevent unauthorized updates.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24742

Affected Products

Logo Slider/Showcase