Access Control Bypass in WP Cerber by WordPress
CVE-2021-37598
5.3MEDIUM
What is CVE-2021-37598?
The WP Cerber plugin for WordPress, prior to version 8.9.3, is susceptible to an access control bypass vulnerability. This issue allows unauthorized users to manipulate access to the /wp-json endpoint by appending a trailing '?' character to the URL. As a result, sensitive data may be exposed and security measures could be undermined. It is crucial for users of WP Cerber to update to the latest version to mitigate this risk and enhance their site's security.