CVE · Medium

CVE-2021-38312 — Redux Framework [redux-framework] < 4.2.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-38312 Redux Framework [redux-framework] < 4.2.13 Improper Handling of Insufficient Permissions or Privileges Medium 6.5 < 4.2.13 4.2.13 2021-09-01

CVE-2021-38312

The Redux Framework plugin through version 4.2.11 contained an authorization flaw in its REST API endpoints for the "redux/v1/templates/" route. The permissions check inadequately validated user capabilities by only requiring the `edit_posts` capability, which is available to contributors and other lower-privileged roles. This vulnerability allowed such users to install arbitrary plugins from the WordPress plugin repository and modify any posts on the site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.