CVE-2021-38314

MEDIUM NUCLEI

Gutenberg Template Library & Redux Framework < 4.2.11 - Information Disclosure

Title source: rule

Description

The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash of the site URL with a known salt value of '-redux' and an md5 hash of the previous hash with a known salt value of '-support'. These AJAX actions could be used to retrieve a list of active plugins and their versions, the site's PHP version, and an unsalted md5 hash of site’s `AUTH_KEY` concatenated with the `SECURE_AUTH_KEY`.

Exploits (7)

nomisec WORKING POC 7 stars
by orangmuda · poc
https://github.com/orangmuda/CVE-2021-38314
nomisec WORKING POC 6 stars
by phrantom · poc
https://github.com/phrantom/cve-2021-38314
nomisec WORKING POC 4 stars
by akhilkoradiya · poc
https://github.com/akhilkoradiya/CVE-2021-38314
nomisec WORKING POC 2 stars
by twseptian · poc
https://github.com/twseptian/cve-2021-38314
nomisec WORKING POC 1 stars
by 0xGabe · poc
https://github.com/0xGabe/CVE-2021-38314
nomisec WORKING POC 1 stars
by c0ff33b34n · poc
https://github.com/c0ff33b34n/CVE-2021-38314
nomisec WORKING POC 1 stars
by shubhayu-64 · poc
https://github.com/shubhayu-64/CVE-2021-38314

Nuclei Templates (1)

WordPress Redux Framework <=4.2.11 - Information Disclosure
MEDIUMby meme-lord

Scores

CVSS v3 5.3
EPSS 0.9162
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200 CWE-916 CWE-760
Status published
Products (1)
redux/gutenberg_template_library_\&_redux_framework < 4.2.11
Published Sep 02, 2021
Tracked Since Feb 18, 2026