First published: Mon Nov 01 2021(Updated: )
The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Radiustheme Logo Slider And Showcase | <1.3.37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-24742.
The title of this vulnerability is 'The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin…'
The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.
The affected software is the Radiustheme Logo Slider And Showcase WordPress plugin version up to and excluding 1.3.37.
The severity of this vulnerability is medium with a CVSS score of 6.5.