AutomatorWP <= 1.7.5 - Privilege Escalation
2021-09-28 00:00
apple502jStrategic Overview
StatusPatched in 1.7.6
Affected PluginAutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress
Affected Version
< 1.7.6CVSS8.8High
CVE
CVE-2021-24717Vulnerability Overview
The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.
Technical Analysis
REMEDIATION: Update to version 1.7.6, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C