PT-2021-16324 · WordPress · Bulk Datetime Change

Apple502J

·

Published

2021-11-29

·

Updated

2022-10-24

·

CVE-2021-24842

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Bulk Datetime Change WordPress plugin versions prior to 1.12
Description: The issue allows users with Contributor roles to list private post titles of other users and change the posted date of other users' posts due to a lack of capability checks.
Recommendations: For versions prior to 1.12, update to version 1.12 or later to resolve the issue. As a temporary workaround, consider restricting the Contributor role's capabilities to prevent unauthorized access to private posts and their modification.

Exploit

Fix

Incorrect Authorization

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-24842

Affected Products

Bulk Datetime Change