CVE-2021-24500
Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.
Varias acciones AJAX disponibles en el tema de WordPress de Workreap versiones anteriores a 2.2.2, carecían de protecciones de tipo CSRF, además de permitir referencias directas a objetos no seguros que no estaban comprendidas. Esto permite a un atacante engañar a un usuario conectado para que envíe una petición POST al sitio vulnerable, modificando o eliminando potencialmente objetos arbitrarios en el sitio objetivo
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-07-02 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-283: Unverified Ownership
- CWE-284: Improper Access Control
- CWE-352: Cross-Site Request Forgery (CSRF)
- CWE-862: Missing Authorization
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://jetpack.com/2021/07/07/multiple-vulnerabilities-in-workreap-theme | 2024-08-03 | |
https://wpscan.com/vulnerability/0c4b5ecc-54d0-45ec-9f92-b2ca3cadbe56 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Amentotech Search vendor "Amentotech" | Workreap Search vendor "Amentotech" for product "Workreap" | < 2.2.2 Search vendor "Amentotech" for product "Workreap" and version " < 2.2.2" | wordpress |
Affected
|