Access Control Bypass in WP Cerber by WordPress
CVE-2021-37598
5.3MEDIUM
Summary
The WP Cerber plugin for WordPress, prior to version 8.9.3, is susceptible to an access control bypass vulnerability. This issue allows unauthorized users to manipulate access to the /wp-json endpoint by appending a trailing '?' character to the URL. As a result, sensitive data may be exposed and security measures could be undermined. It is crucial for users of WP Cerber to update to the latest version to mitigate this risk and enhance their site's security.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved