First published: Mon Sep 27 2021(Updated: )
The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpdeveloper Countdown Block | <1.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24633 is a vulnerability in the Countdown Block WordPress plugin before version 1.1.2.
The severity of CVE-2021-24633 is medium with a severity value of 4.3.
CVE-2021-24633 allows any authenticated user, such as a Subscriber, to modify post contents displayed to users in the Countdown Block WordPress plugin before version 1.1.2.
The affected software version of CVE-2021-24633 is up to, but excluding, version 1.1.2 of the Countdown Block WordPress plugin.
Yes, upgrading to version 1.1.2 or later of the Countdown Block WordPress plugin fixes CVE-2021-24633.