Tab – Accordion, FAQ < 1.3.2 - Unauthenticated Arbitrary Tab Modification
2021-12-06 00:00
Brandon James Roldan (tomorrowisnew)Strategic Overview
StatusPatched in 1.3.2
Affected PluginTab – Accordion, FAQ
Affected Version
< 1.3.2CVSS7.5High
CVE
CVE-2021-24831Vulnerability Overview
All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete arbitrary tabs.
Technical Analysis
REMEDIATION: Update to version 1.3.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C