Record summary

CVE-2021-37598 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMWP Cerber < 8.9.3 - Broken Access ControlCVSS 5.3

WP Cerber < 8.9.3 contains a bypass of /wp-json access control caused by improper handling of trailing '?' character, letting unauthorized users access protected REST API endpoints, exploit requires sending a request with a trailing '?'.

Impact

Unauthorized users can access protected REST API endpoints, potentially leading to information disclosure or further exploitation.

Remediation

Update to version 8.9.3 or later.

WeaknessesCWE-863
Authorstheamanrawat
Template tagscvecve2021wordpresswp-cerberaccess-controlrest-apiexposureauth-bypass
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Source: ProjectDiscovery

References

3