Squaretype Modern Blog < 3.0.4 - Unauthenticated Private/Schedule Posts Disclosure
Vulnerability Description
The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-24840
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Emil Kylander Edwartz
More from Unknown
View All →Affected Vendor
Unknown
View all reports →