PT-2021-16324 · WordPress · Bulk Datetime Change
Apple502J
·
Published
2021-11-29
·
Updated
2022-10-24
·
CVE-2021-24842
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Bulk Datetime Change WordPress plugin versions prior to 1.12
Description:
The issue allows users with Contributor roles to list private post titles of other users and change the posted date of other users' posts due to a lack of capability checks.
Recommendations:
For versions prior to 1.12, update to version 1.12 or later to resolve the issue. As a temporary workaround, consider restricting the Contributor role's capabilities to prevent unauthorized access to private posts and their modification.
Exploit
Fix
Incorrect Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bulk Datetime Change