First published: Wed Jun 07 2023(Updated: )
The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, 1.14.3. This makes it possible for unauthenticated attackers to update arbitrary options on a site that can be used to create new administrative user accounts or redirect unsuspecting site visitors.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Valvepress Pinterest Automatic Pin | <4.14.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-4380 is rated as a critical vulnerability due to the potential for unauthorized access by unauthenticated attackers.
CVE-2021-4380 allows unauthenticated users to bypass authorization checks, potentially leading to exploitation of the affected WordPress site.
CVE-2021-4380 affects the Pinterest Automatic plugin for WordPress versions up to and including 1.14.3.
To fix CVE-2021-4380, update the Pinterest Automatic plugin to version 1.14.4 or later.
CVE-2021-4380 poses significant security risks as it allows unauthorized actions to be performed on a WordPress site.