4
CVSSv2

CVE-2021-24633

Published: 27/09/2021 Updated: 05/11/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

The Countdown Block WordPress plugin prior to 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wpdeveloper countdown block