CVE-2021-24845
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/12/2021
Last modified:
29/07/2022
Description
The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status which can be used to retrieve arbitrary content. This way, users with a role as low as Contributor can gain access to content they are not supposed to.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:improved_include_page_project:improved_include_page:*:*:*:*:*:wordpress:*:* | 1.2 (including) |
To consult the complete list of CPE names with products and versions, see this page



