CVE-2021-24742

Publication date

2021-11-01 08:46:15

Family

WPScan

State

PUBLISHED

Description

The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugins settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.