The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of unauthorized actions such as importing data, uploading arbitrary files, deleting arbitrary files, and more.
History

Wed, 30 Oct 2024 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:kaswara_project:kaswara:*:*:*:*:*:wordpress:*:*

Wed, 16 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Kaswara Project
Kaswara Project kaswara
CPEs cpe:2.3:a:kaswara_project:kaswara:*:*:*:*:*:*:*:*
Vendors & Products Kaswara Project
Kaswara Project kaswara
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 07:00:00 +0000

Type Values Removed Values Added
Description The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of unauthorized actions such as importing data, uploading arbitrary files, deleting arbitrary files, and more.
Title Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-10-16T06:43:31.059Z

Updated: 2024-10-16T18:06:05.354Z

Reserved: 2024-10-15T18:33:45.075Z

Link: CVE-2021-4448

cve-icon Vulnrichment

Updated: 2024-10-16T18:01:35.413Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-16T07:15:10.980

Modified: 2024-10-30T18:18:58.743

Link: CVE-2021-4448

cve-icon Redhat

No data.