Controlled Admin Access <= 1.5.1 - Improper Access Control & Privilege Escalation
2021-03-23 00:00
R3N0Strategic Overview
StatusPatched in 1.5.2
Affected PluginControlled Admin Access
Affected Version
< 1.5.2CVSS9.8Critical
CVE
CVE-2021-24215Vulnerability Overview
An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.
Technical Analysis
REMEDIATION: Update to version 1.5.2, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C