CVE-2021-24633: Countdown Block < 1.1.2 - Missing Authorisation in AJAX action
The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the ebwriteblockcss AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24633?
CVE-2021-24633 is a vulnerability in the Countdown Block WordPress plugin before version 1.1.2.
What is the severity of CVE-2021-24633?
The severity of CVE-2021-24633 is medium with a severity value of 4.3.
How does CVE-2021-24633 affect the Countdown Block plugin?
CVE-2021-24633 allows any authenticated user, such as a Subscriber, to modify post contents displayed to users in the Countdown Block WordPress plugin before version 1.1.2.
What is the affected software version of CVE-2021-24633?
The affected software version of CVE-2021-24633 is up to, but excluding, version 1.1.2 of the Countdown Block WordPress plugin.
Is there a fix available for CVE-2021-24633?
Yes, upgrading to version 1.1.2 or later of the Countdown Block WordPress plugin fixes CVE-2021-24633.