CVE-2021-24840

The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:codesupply:squaretype:*:*:*:*:*:wordpress:*:*

Information

Published : 2021-11-08 10:15

Updated : 2021-11-12 20:03


NVD link : CVE-2021-24840

Mitre link : CVE-2021-24840


JSON object : View

CWE
CWE-639

Authorization Bypass Through User-Controlled Key

Advertisement

dedicated server usa

Products Affected

codesupply

  • squaretype