CVE-2021-24717: AutomatorWP < 1.7.6 - Missing Authorization and Privilege Escalation
The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24717?
CVE-2021-24717 is classified as a medium severity vulnerability due to its potential for privilege escalation and unauthorized information disclosure.
How do I fix CVE-2021-24717?
To fix CVE-2021-24717, update the AutomatorWP WordPress plugin to version 1.7.6 or later.
Who is affected by CVE-2021-24717?
CVE-2021-24717 affects users with Subscriber roles on WordPress sites using AutomatorWP plugin versions prior to 1.7.6.
What types of information can be disclosed due to CVE-2021-24717?
Due to CVE-2021-24717, an attacker can enumerate automations, access titles of private posts, and disclose user emails.
What actions can a compromised account perform in CVE-2021-24717?
A compromised account can call functions and perform privilege escalation through Ajax actions due to CVE-2021-24717.