CVE Database /
CVE-2021-38312
CVE · Medium
CVE-2021-38312 — Redux Framework [redux-framework] < 4.2.13
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-38312
|
Redux Framework [redux-framework] < 4.2.13 |
Improper Handling of Insufficient Permissions or Privileges |
Medium
6.5
|
< 4.2.13
|
4.2.13 |
2021-09-01 |
—
|
CVE-2021-38312
The Redux Framework plugin through version 4.2.11 contained an authorization flaw in its REST API endpoints for the "redux/v1/templates/" route. The permissions check inadequately validated user capabilities by only requiring the `edit_posts` capability, which is available to contributors and other lower-privileged roles. This vulnerability allowed such users to install arbitrary plugins from the WordPress plugin repository and modify any posts on the site.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings