Advanced Cron Manager <= 2.4.1 - Subscriber+ Arbitrary Events/Schedules Creation/Deletion

2022-01-04 00:00
Krzysztof Zając

Strategic Overview

Status
Patched in 2.4.2
Affected Version< 2.4.2
CVSS4.3Medium
CVECVE-2021-25084
View all Advanced Cron Manager – debug & control vulnerabilities

Vulnerability Overview

The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example

Technical Analysis

REMEDIATION: Update to version 2.4.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C