CVE-2021-24717

HIGH

AutomatorWP <1.7.6 - Info Disclosure/Privilege Escalation

Title source: llm
STIX 2.1

Description

The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/5916ea42-eb33-463d-8528-2a142805c91f

Scores

CVSS v3 8.8
EPSS 0.0129
EPSS Percentile 66.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (1)
automatorwp/automatorwp < 1.7.6
Published Nov 01, 2021
Tracked Since Feb 18, 2026