CVE-2021-24215

Publication date

2021-04-12 14:00:48

Family

WPScan

State

PUBLISHED

Description

An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.