CVE-2021-24677

CVE-2021-24677: Find My Blocks < 3.4.0 - Private Post Titles Disclosure

Vendor Unknown
Product Find My Blocks
Weakness CWE-862 · Missing authorization
Published October 18, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow unauthenticated users to enumerate private posts' titles.

Key dates

02Disclosure timeline

October 18, 2021 CVE published
August 3, 2024 Record updated