// For flags

CVE-2021-24742

Logo Slider and Showcase < 1.3.37 - Editor Plugin's Settings Update

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.

El plugin Logo Slider and Showcase de WordPress versiones anteriores a 1.3.37 permite a usuarios del editor actualizar la configuración del plugin por medio de la acción AJAX rtWLSSettings porque usa un nonce para la autorización en lugar de una comprobación de capacidad

*Credits: apple502j
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-01-14 CVE Reserved
  • 2021-10-04 CVE Published
  • 2023-05-25 EPSS Updated
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-863: Incorrect Authorization
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Radiustheme
Search vendor "Radiustheme"
Logo Slider And Showcase
Search vendor "Radiustheme" for product "Logo Slider And Showcase"
< 1.3.37
Search vendor "Radiustheme" for product "Logo Slider And Showcase" and version " < 1.3.37"
wordpress
Affected