CVE Database
/

CVE-2021-25084

Back to search

CVE-2021-25084

Published: Feb 7, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example

VendorProductVersions

Unknown

Advanced Cron Manager

affected
2.4.2 - < 2.4.2

Unknown

Advanced Cron Manager Pro

affected
2.5.3 - < 2.5.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now