4.3
CVSSv3

CVE-2021-25084

Published: 07/02/2022 Updated: 01/03/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

The Advanced Cron Manager WordPress plugin prior to 2.4.2 and Advanced Cron Manager Pro WordPress plugin prior to 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bracketspace advanced cron manager