CVE-2021-24717 Information
Jun 07, 2022
cve
Description
The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations disclose title of private posts or user emails call functions or perform privilege escalation via Ajax actions.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://wpscan.com/vulnerability/5916ea42-eb33-463d-8528-2a142805c91f
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: