Squaretype - Modern Blog WordPress Theme < 3.0.4 - Authorization Bypass

2021-10-11 00:00
Emil Kylander Edwartz

Strategic Overview

Status
Patched in 3.0.4
Affected Version< 3.0.4
CVSS5.3Medium
CVECVE-2021-24840
View all Squaretype - Modern Blog WordPress Theme vulnerabilities

Vulnerability Overview

The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.

Technical Analysis

REMEDIATION: Update to version 3.0.4, or a newer patched version --- IDENTIFIER: CWE-639 (Authorization Bypass Through User-Controlled Key) The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C