CVE-2021-24148 Information
Jun 07, 2022
cve
Description
A business logic issue in the MStore API WordPress plugin versions before 3.2.0 had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://wpscan.com/vulnerability/bf5ddc43-974d-41fa-8276-c1a27d3cc882
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: