WordPress security by component
Controlled Admin Access
Plugin description
Controlled Admin Access is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 07, 2023; the highest published CVSS base score is 9.9.
Plugin slug:
controlled-admin-accessLatest vulnerability
CVE-2021-4360: Controlled Admin Access: Privilege escalation or authentication bypass
Controlled Admin Access is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Jun 07, 2023 |
CVE-2021-4360
Controlled Admin Access: Privilege escalation or authentication bypass
Controlled Admin Access is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE9.9
NVD8.8
|
| Apr 12, 2021 |
CVE-2021-24215
Controlled Admin Access: A security weakness
Controlled Admin Access is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVEPending
NVD9.8
|