Improper access control in WP Upload Restriction - CVE-2021-34627
Published: August 24, 2021
WP Upload Restriction
Sajjad Hossain Sagor
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the "getSelectedMimeTypesByRole" function. A remote authenticated attacker can bypass implemented security restrictions and retrieve approved mime types for any given role.