CVE-2021-24215

CRITICAL NUCLEI

Wpruby Controlled Admin Access < 1.5.2 - Improper Access Control

Title source: rule

Description

An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.

Nuclei Templates (1)

Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access Control & Privilege Escalation
CRITICALVERIFIEDby r3Y3r53
Shodan: http.html:/wp-content/plugins/controlled-admin-access/
FOFA: body=/wp-content/plugins/controlled-admin-access/

Scores

CVSS v3 9.8
EPSS 0.5459
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284 CWE-425
Status published
Products (1)
wpruby/controlled_admin_access < 1.5.2
Published Apr 12, 2021
Tracked Since Feb 18, 2026