Vulnerabilities > Shapedplugin

DATE CVE VULNERABILITY TITLE RISK
2021-12-21 CVE-2021-24739 Authorization Bypass Through User-Controlled Key vulnerability in Shapedplugin Logo Carousel
The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature
network
low complexity
shapedplugin CWE-639
8.1