Information disclosure in Gutenberg Template Library & Redux Framework - CVE-2021-38314
Published: September 3, 2021 / Updated: April 30, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application in the "includes" function in "redux-core/class-redux-core.php" file. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
How to mitigate CVE-2021-38314
Links to Public Exploits and PoC-codes
- Exploit #9021 - CVE-2021-38314 (Exploit in python3 to explore CVE-2021-38314 in Redux Framework a wordpress plugin ) (April 30, 2023)
- Exploit #8355 - CVE-2021-38314 (CVE-2021-38314 Python Exploit) (September 8, 2022)
- Exploit #8086 - CVE-2021-38314 (Python exploit for CVE-2021-38314) (June 27, 2022)
- Exploit #7531 - CVE-2021-38314 ( Unauthenticated Sensitive Information Disclosure (CVE-2021–38314).) (March 23, 2022)
- Exploit #7106 - cve-2021-38314 () (December 7, 2021)