Vulnerabilities > CVE-2021-24739 - Authorization Bypass Through User-Controlled Key vulnerability in Shapedplugin Logo Carousel

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
shapedplugin
CWE-639

Summary

The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature