CVE-2021-24779
WP Debugging <= 2.10.2 - Unauthenticated Plugin Settings Update
mediumMissing Authorization
6.5
CVSS Score
6.5
CVSS Score
medium
Severity
2.11.0
Patched in
848d
Time to patch
Description
The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF checks, as a result, the settings can be updated by unauthenticated users.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NAttack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
None
Confidentiality
High
Integrity
None
Availability
Technical Details
Affected versions
<=2.10.2PublishedSeptember 27, 2021
Last updatedJanuary 22, 2024
Affected pluginwp-debugging
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.