First published: Mon Nov 08 2021(Updated: )
The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Codesupply Squaretype | <3.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24840 is considered a high severity vulnerability due to its potential to expose private and scheduled posts.
To fix CVE-2021-24840, update the Squaretype WordPress theme to version 3.0.4 or later.
CVE-2021-24840 is a security vulnerability that allows unauthenticated users to exploit REST endpoints.
CVE-2021-24840 affects users of the Squaretype WordPress theme versions prior to 3.0.4.
Attackers can retrieve private and scheduled posts by manipulating query_vars in REST API requests due to a lack of validation.