mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-12 09:21:42 +02:00
926 B
926 B
CVE-2021-24840
Description
The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.
POC
Reference
- https://wpscan.com/vulnerability/971302fd-4e8b-4c6a-818f-3a42c7fb83ef
- https://wpscan.com/vulnerability/971302fd-4e8b-4c6a-818f-3a42c7fb83ef
Github
No PoCs found on GitHub currently.