Vulnerabilities > CVE-2021-24717 - Incorrect Authorization vulnerability in Automatorwp

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
automatorwp
CWE-863

Summary

The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

Vulnerable Configurations

Part Description Count
Application
Automatorwp
1

Common Weakness Enumeration (CWE)