Improper access control in WP Upload Restriction - CVE-2021-34627

 

Improper access control in WP Upload Restriction - CVE-2021-34627

Published: August 24, 2021


Vulnerability identifier: #VU56050
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-34627
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
WP Upload Restriction
Software vendor:
Sajjad Hossain Sagor

Description

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in the "getSelectedMimeTypesByRole" function. A remote authenticated attacker can bypass implemented security restrictions and retrieve approved mime types for any given role.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links