Insert Pages <= 3.6.1 - Contributor+ Arbitrary Posts/Pages Access

2021-10-18 00:00
Francesco Carlucci

Strategic Overview

Status
Patched in 3.7.0
Affected PluginInsert Pages
Affected Version<= 3.6.1
CVSS4.3Medium
CVECVE-2021-24851
View all Insert Pages vulnerabilities

Vulnerability Overview

The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and metadata from arbitrary posts/pages regardless of their author and status (ie private), using a shortcode. Password protected posts/pages are not affected by such issue.

Technical Analysis

REMEDIATION: Update to version 3.7.0, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C