Vulnerabilities > CVE-2021-24906 - Missing Authorization vulnerability in Wp-Experts Protect WP Admin

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
wp-experts
CWE-862

Summary

The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request

Vulnerable Configurations

Part Description Count
Application
Wp-Experts
1

Common Weakness Enumeration (CWE)