{
    "id": "CVE-2021-24215",
    "published": "2021-04-12 14:15:15",
    "last_modified": "2026-06-17 03:39:36",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-284",
    "description": "An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.",
    "epss_score": "0.09733",
    "epss_percentile": "0.95391",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-05 18:17:25",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (9.8), but no sign of active exploitation."
    },
    "products": [
        {
            "vendor": "wpruby",
            "product": "controlled_admin_access"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "https://m0ze.ru/vulnerability/%5B2021-03-18%5D-%5BWordPress%5D-%5BCWE-284%5D-Controlled-Admin-Access-WordPress-Plugin-v1.4.0.txt",
        "https://wpscan.com/vulnerability/eec0f29f-a985-4285-8eed-d1855d204a20",
        "https://m0ze.ru/vulnerability/%5B2021-03-18%5D-%5BWordPress%5D-%5BCWE-284%5D-Controlled-Admin-Access-WordPress-Plugin-v1.4.0.txt",
        "https://wpscan.com/vulnerability/eec0f29f-a985-4285-8eed-d1855d204a20"
    ]
}