{"api_version":"1","generated_at":"2026-07-23T17:14:32+00:00","cve":"CVE-2021-24881","urls":{"html":"https://cve.report/CVE-2021-24881","api":"https://cve.report/api/cve/CVE-2021-24881.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-24881","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-24881"},"summary":{"title":"CVE-2021-24881","description":"The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request.","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2023-01-23 15:15:00","updated_at":"2023-11-07 03:31:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/0967303d-ea49-4993-84eb-a7ec97240071","name":"https://wpscan.com/vulnerability/0967303d-ea49-4993-84eb-a7ec97240071","refsource":"MISC","tags":[],"title":"Passster < 3.5.5.9 - Protection Bypass & Arbitrary Post Access WordPress Security Vulnerability","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-24881","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-24881","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"24881","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"passster_project","cpe5":"passter","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2021-24881","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-287 Improper Authentication"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Unknown","product":{"product_data":[{"product_name":"Passster","version":{"version_data":[{"version_value":"0","version_affected":"="}]}}]}}]}},"references":{"reference_data":[{"url":"https://wpscan.com/vulnerability/0967303d-ea49-4993-84eb-a7ec97240071","refsource":"MISC","name":"https://wpscan.com/vulnerability/0967303d-ea49-4993-84eb-a7ec97240071"}]},"generator":{"engine":"WPScan CVE Generator"},"source":{"discovery":"EXTERNAL"},"credits":[{"lang":"en","value":"dc11"},{"lang":"en","value":"WPScan"}]},"nvd":{"publishedDate":"2023-01-23 15:15:00","lastModifiedDate":"2023-11-07 03:31:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:passster_project:passter:*:*:*:*:*:wordpress:*:*","versionEndExcluding":"3.5.5.9","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"24881","Ordinal":"199643","Title":"CVE-2021-24881","CVE":"CVE-2021-24881","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"24881","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}