Page/Post Content Shortcode <= 1.0 - Missing Authorization

2021-11-15 00:00
Francesco Carlucci

Strategic Overview

Status
Unpatched
Affected Version<= 1.0
CVSS4.3Medium
CVECVE-2021-24819
View all Page/Post Content Shortcode vulnerabilities

Vulnerability Overview

The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C