VulnerabilityModified
CVE-2021-24215
An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2.
CRITICAL 9.8EPSS 9.73%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 9.73% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-425
- Affected
- wpruby/controlled admin access
- Source
- contact@wpscan.com
References
- https://m0ze.ru/vulnerability/%5B2021-03-18%5D-%5BWordPress%5D-%5BCWE-284%5D-Controlled-Admin-Access-WordPress-Plugin-v1.4.0.txt
- https://wpscan.com/vulnerability/eec0f29f-a985-4285-8eed-d1855d204a20Exploit, Third Party Advisory
- https://m0ze.ru/vulnerability/%5B2021-03-18%5D-%5BWordPress%5D-%5BCWE-284%5D-Controlled-Admin-Access-WordPress-Plugin-v1.4.0.txt
- https://wpscan.com/vulnerability/eec0f29f-a985-4285-8eed-d1855d204a20Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.