Vulnerabilities > CVE-2021-24788 - Unspecified vulnerability in Batch CAT Project Batch CAT 0.3
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are available for all roles. As a result, any authenticated user (including simple subscribers) can add/set/delete arbitrary categories to posts.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |