Back to search
CVE-2021-24819
Published: Dec 13, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors.
| Vendor | Product | Versions |
|---|---|---|
Unknown | Page/Post Content Shortcode | affected 1.0 - <= 1.0 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now