SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-24215

An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2.

CRITICAL 9.8EPSS 9.73%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (9.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
9.73% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-284, CWE-425
Affected
wpruby/controlled admin access
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.