Workreap Theme < 2.2.2 - Authorization Bypass
2021-06-29 00:00
Harald EilertsenStrategic Overview
StatusPatched in 2.2.2
Affected Version
< 2.2.2CVSS8.1High
CVE
CVE-2021-24501Vulnerability Overview
The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifying or deleting objects. This allowed a logged in user to modify or delete objects belonging to other users on the site.
Technical Analysis
REMEDIATION: Update to version 2.2.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C