Vulnerabilities > CVE-2021-24842 - Incorrect Authorization vulnerability in Bulk Datetime Change Project Bulk Datetime Change
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |