CVE-2021-24739: Logo Carousel < 3.4.2 - Unauthorised Private Post Access
The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-24739.
What is the severity rating of CVE-2021-24739?
CVE-2021-24739 has a severity rating of 8.1 (High).
What does CVE-2021-24739 allow users to do?
CVE-2021-24739 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature of the Logo Carousel WordPress plugin.
Which version of the Logo Carousel WordPress plugin is affected by CVE-2021-24739?
Versions of the Logo Carousel WordPress plugin up to and excluding 3.4.2 are affected by CVE-2021-24739.
Is there any reference for more information about CVE-2021-24739?
Yes, you can find more information about CVE-2021-24739 at the following reference: [link](https://wpscan.com/vulnerability/2afadc76-93ad-47e1-a224-e442ac41cbce).