CVE-2021-24783: Post Expirator < 2.6.0 - Contributor+ Arbitrary Post Schedule Deletion
Published Nov 8, 2021
·Updated
The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of arbitrary posts.
Affected Software
1 affected component
PublishPress Post Expirator Wordpress<2.6.0
Event History
Nov 8, 2021
CVE Published
via MITRE·05:35 PM
Data Sourced
via MITRE·05:35 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24783?
CVE-2021-24783 is rated as a medium severity vulnerability due to its potential impact on user permissions.
2
How do I fix CVE-2021-24783?
To fix CVE-2021-24783, update the Post Expirator WordPress plugin to version 2.6.0 or later.
3
What does CVE-2021-24783 allow an attacker to do?
CVE-2021-24783 allows users with low-level permissions, such as Contributors, to schedule the deletion of arbitrary posts.
4
Which versions of the Post Expirator plugin are affected by CVE-2021-24783?
CVE-2021-24783 affects all versions of the Post Expirator plugin prior to 2.6.0.
5
What type of users are exploited in CVE-2021-24783?
CVE-2021-24783 can be exploited by users with roles as low as Contributor.