Vulnerabilities > CVE-2021-24842 - Incorrect Authorization vulnerability in Bulk Datetime Change Project Bulk Datetime Change

047910
CVSS 5.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE

Summary

The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.

Vulnerable Configurations

Part Description Count
Application
Bulk_Datetime_Change_Project
1

Common Weakness Enumeration (CWE)