Squaretype - Modern Blog WordPress Theme < 3.0.4 - Authorization Bypass
2021-10-11 00:00
Emil Kylander EdwartzStrategic Overview
StatusPatched in 3.0.4
Affected ThemeSquaretype - Modern Blog WordPress Theme
Affected Version
< 3.0.4CVSS5.3Medium
CVE
CVE-2021-24840Vulnerability Overview
The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.
Technical Analysis
REMEDIATION: Update to version 3.0.4, or a newer patched version --- IDENTIFIER: CWE-639 (Authorization Bypass Through User-Controlled Key) The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C