CVE-2021-24215
9.8
CRITICAL · CVSS 3.1 · EPSS 9.7% (pctl 95)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 9.73% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-284 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-04-12 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| wpruby | controlled admin access |
References
- https://m0ze.ru/vulnerability/%5B2021-03-18%5D-%5BWordPress%5D-%5BCWE-284%5D-Controlled-Admin-Access-WordPress-Plugin-v1.4.0.txt
- https://wpscan.com/vulnerability/eec0f29f-a985-4285-8eed-d1855d204a20
- https://m0ze.ru/vulnerability/%5B2021-03-18%5D-%5BWordPress%5D-%5BCWE-284%5D-Controlled-Admin-Access-WordPress-Plugin-v1.4.0.txt
- https://wpscan.com/vulnerability/eec0f29f-a985-4285-8eed-d1855d204a20
→ the Explorer · watch your stack · NVD