CVE-2021-24289
Summary
| CVE | CVE-2021-24289 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-17 17:15:00 UTC |
| Updated | 2021-05-24 18:28:00 UTC |
| Description | There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | De-baat | Store Locator Plus | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Attention Required! | Cloudflare | CONFIRM | wpscan.com | |
| Severe Unpatched Vulnerabilities Leads to Closure of Store Locator Plus Plugin | MISC | www.wordfence.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Chloe Chamberland
There are currently no legacy QID mappings associated with this CVE.