CVE-2021-24501: Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actions
Published Aug 9, 2021
·Updated
The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifying or deleting objects. This allowed a logged in user to modify or delete objects belonging to other users on the site.
Affected Software
1 affected component
Amentotech Workreap Wordpress<2.2.2
Event History
Aug 9, 2021
CVE Published
via MITRE·10:04 AM
Data Sourced
via MITRE·10:04 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24501?
The severity of CVE-2021-24501 is high with a CVSS score of 8.1.
2
How can I fix the vulnerability CVE-2021-24501?
To fix CVE-2021-24501, users should update the Workreap WordPress theme to version 2.2.2 or higher to address the missing authorization checks.