PT-2021-16324 · WordPress · Bulk Datetime Change

·

CVE-2021-24842

·

Published

2021-11-29

·

Updated

2022-10-24

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Bulk Datetime Change WordPress plugin versions prior to 1.12
Description: The issue allows users with Contributor roles to list private post titles of other users and change the posted date of other users' posts due to a lack of capability checks.
Recommendations: For versions prior to 1.12, update to version 1.12 or later to resolve the issue. As a temporary workaround, consider restricting the Contributor role's capabilities to prevent unauthorized access to private posts and their modification.

Exploit

Fix

Incorrect Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24842

Affected Products

Bulk Datetime Change