CVE-2021-4366: PWA for WP & AMP < = 1.7.32 - Missing Authorization
The PWA for WP & AMP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the pwaforwpupdatefeaturesoptions function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to change the otherwise restricted settings within the plugin.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-4366?
CVE-2021-4366 is a vulnerability in the PWA for WP & AMP plugin for WordPress.
How severe is CVE-2021-4366?
CVE-2021-4366 has a severity level of medium (4.3).
What is the description of CVE-2021-4366?
CVE-2021-4366 is an authorization bypass vulnerability in the PWA for WP & AMP plugin for WordPress, allowing authenticated attackers to change restricted settings.
Which software versions are affected by CVE-2021-4366?
Versions up to and including 1.7.33 of the PWA for WP & AMP plugin for WordPress are affected by CVE-2021-4366.
How can I fix CVE-2021-4366?
To fix CVE-2021-4366, update the PWA for WP & AMP plugin for WordPress to version 1.7.34 or later.