The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of unauthorized actions such as importing data, uploading arbitrary files, deleting arbitrary files, and more.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Oct 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:kaswara_project:kaswara:*:*:*:*:*:wordpress:*:* |
Wed, 16 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Kaswara Project
Kaswara Project kaswara |
|
CPEs | cpe:2.3:a:kaswara_project:kaswara:*:*:*:*:*:*:*:* | |
Vendors & Products |
Kaswara Project
Kaswara Project kaswara |
|
Metrics |
ssvc
|
Wed, 16 Oct 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of unauthorized actions such as importing data, uploading arbitrary files, deleting arbitrary files, and more. | |
Title | Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-16T06:43:31.059Z
Updated: 2024-10-16T18:06:05.354Z
Reserved: 2024-10-15T18:33:45.075Z
Link: CVE-2021-4448
Vulnrichment
Updated: 2024-10-16T18:01:35.413Z
NVD
Status : Analyzed
Published: 2024-10-16T07:15:10.980
Modified: 2024-10-30T18:18:58.743
Link: CVE-2021-4448
Redhat
No data.