Controlled Admin Access < 1.5.6 - Privilege Escalation
2021-03-30 00:00
Jerome BruandetStrategic Overview
StatusPatched in 1.5.6
Affected PluginControlled Admin Access
Affected Version
< 1.5.6CVSS9.9Critical
CVE
CVE-2021-4360Vulnerability Overview
The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted access.
Technical Analysis
REMEDIATION: Update to version 1.5.6, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C