CVE-2021-24831

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
03/01/2022
Last modified:
31/08/2023

Description

All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete arbitrary tabs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rich-web:tab:*:*:*:*:*:wordpress:*:* 1.3.2 (excluding)