CVE-2021-4380: Pinterest Automatic <= 4.14.3 - Unuathenticated Arbitrary Options Update
The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wppinterestautomaticparserequest' function and the 'processform.php' script in versions up to, and including, 1.14.3. This makes it possible for unauthenticated attackers to update arbitrary options on a site that can be used to create new administrative user accounts or redirect unsuspecting site visitors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4380?
CVE-2021-4380 is rated as a critical vulnerability due to the potential for unauthorized access by unauthenticated attackers.
How does CVE-2021-4380 affect WordPress sites?
CVE-2021-4380 allows unauthenticated users to bypass authorization checks, potentially leading to exploitation of the affected WordPress site.
What versions of the Pinterest Automatic plugin are affected by CVE-2021-4380?
CVE-2021-4380 affects the Pinterest Automatic plugin for WordPress versions up to and including 1.14.3.
How do I fix CVE-2021-4380?
To fix CVE-2021-4380, update the Pinterest Automatic plugin to version 1.14.4 or later.
What security implications does CVE-2021-4380 have for WordPress users?
CVE-2021-4380 poses significant security risks as it allows unauthorized actions to be performed on a WordPress site.