PT-2021-16333 · WordPress · Insert Pages

Francesco Carlucci

·

Published

2021-11-17

·

Updated

2022-08-30

·

CVE-2021-24851

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Insert Pages WordPress plugin versions prior to 3.7.0
Description: The issue allows users with a role as low as Contributor to access content and metadata from arbitrary posts or pages, regardless of their author and status, including private ones, using a shortcode. However, password-protected posts or pages are not affected.
Recommendations: For versions prior to 3.7.0, update to version 3.7.0 or later to resolve the issue.

Exploit

Fix

Incorrect Authorization

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-24851

Affected Products

Insert Pages