Unrated severityNVD Advisory· Published Nov 8, 2021· Updated Aug 3, 2024
Squaretype Modern Blog < 3.0.4 - Unauthenticated Private/Schedule Posts Disclosure
CVE-2021-24840
Description
The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.
Affected products
1- Range: 3.0.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/971302fd-4e8b-4c6a-818f-3a42c7fb83efmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.