CVE Published: 01/11/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: WPScan |
Vendor: Unknown |
Product: Logo Slider and Showcase Status : PUBLISHED
CVE-2021-24742 Description
The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin\'s settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.