CVE-2021-38312
Summary
| CVE | CVE-2021-38312 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-02 17:15:00 UTC |
| Updated | 2022-10-27 12:50:00 UTC |
| Description | The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/classes/class-api.php”. The `permissions_callback` used in this file only checked for the `edit_posts` capability which is granted to lower-privileged users such as contributors, allowing such users to install arbitrary plugins from the WordPress repository and edit arbitrary posts. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redux | Gutenberg Template Library Redux Framework | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Over 1 Million Sites Affected by Gutenberg Template Library & Redux Framework Vulnerabilities | MISC | www.wordfence.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Ramuel Gall, Wordfence
Legacy QID Mappings
- 730189 WordPress Gutenberg Template Library And Redux Framework Plugin Multiple Vulnerabilities