CVE-2021-24906

CVE-2021-24906: Protect WP Admin < 3.6.2 - Unauthenticated Plugin Deactivation

Vendor Unknown
Product Protect WP Admin
Weakness CWE-862 · Missing authorization
Published January 24, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request

Key dates

02Disclosure timeline

January 24, 2022 CVE published
August 3, 2024 Record updated

Related vulnerabilities

04Related CVE