Bulk Datetime Change <= 1.11 - Missing Authorisation

2021-10-26 00:00
apple502j

Strategic Overview

Status
Patched in 1.12
Affected PluginBulk Datetime Change
Affected Version< 1.12
CVSS5.4Medium
CVECVE-2021-24842
View all Bulk Datetime Change vulnerabilities

Vulnerability Overview

The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.

Technical Analysis

REMEDIATION: Update to version 1.12, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C