Vulnerabilities > CVE-2021-24717 - Incorrect Authorization vulnerability in Automatorwp

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
automatorwp
CWE-863

Summary

The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

Vulnerable Configurations

Part Description Count
Application
Automatorwp
1

Common Weakness Enumeration (CWE)