// For flags

CVE-2021-24635

Visual Link Preview < 2.2.3 - Unauthorised AJAX Calls

Severity Score

5.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and content of Draft post, 2) Get title of a password-protected post as well as 3) Upload an image from an URL

El plugin Visual Link Preview de WordPress versiones anteriores a 2.2.3, no impone una autorización en varias acciones AJAX y presenta el CSRF nonce mostrado para todos los usuarios autenticados, permitiendo a cualquier usuario autenticado (como el suscriptor) llamarlos y 1) Conseguir y buscar mediante el título y el contenido del Borrador de la entrada, 2) conseguir el título de una entrada protegida por contraseña, así como 3) Cargar una imagen desde una URL

*Credits: apple502j
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-01-14 CVE Reserved
  • 2021-08-18 CVE Published
  • 2023-04-13 EPSS Updated
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-284: Improper Access Control
  • CWE-862: Missing Authorization
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Bootstrapped
Search vendor "Bootstrapped"
Visual Link Preview
Search vendor "Bootstrapped" for product "Visual Link Preview"
< 2.2.3
Search vendor "Bootstrapped" for product "Visual Link Preview" and version " < 2.2.3"
wordpress
Affected