High severity7.5NVD Advisory· Published Jan 24, 2022· Updated Jun 17, 2026
CVE-2021-24906
CVE-2021-24906
Description
The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- WordPress/Protect WP Admindescription
- Range: <3.6.2
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/4204682b-f657-42e1-941c-bee7a245e9fdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.