VYPR

Squaretype

by Awesome Weather Widget Project

CVEs (1)

  • CVE-2021-24840Nov 8, 2021
    risk 0.00cvss epss 0.00

    The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.