Controlled Admin Access <= 1.5.1 - Improper Access Control & Privilege Escalation

2021-03-23 00:00
R3N0

Strategic Overview

Status
Patched in 1.5.2
Affected Version< 1.5.2
CVSS9.8Critical
CVECVE-2021-24215
View all Controlled Admin Access vulnerabilities

Vulnerability Overview

An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.

Technical Analysis

REMEDIATION: Update to version 1.5.2, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C