CVE-2021-24215
CRITICAL NUCLEIWpruby Controlled Admin Access < 1.5.2 - Improper Access Control
Title source: ruleDescription
An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.
Nuclei Templates (1)
Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access Control & Privilege Escalation
CRITICALVERIFIEDby r3Y3r53
Shodan:
http.html:/wp-content/plugins/controlled-admin-access/
FOFA:
body=/wp-content/plugins/controlled-admin-access/
Scores
CVSS v3
9.8
EPSS
0.5459
EPSS Percentile
98.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-284
CWE-425
Status
published
Products (1)
wpruby/controlled_admin_access
< 1.5.2
Published
Apr 12, 2021
Tracked Since
Feb 18, 2026