cleantalk
Vulnerabilities and Security Researches

AutomatorWP – The #1 automator plugin for no-code automation in WordPress, CVE-2021-24717

CVE, Research URL

CVE-2021-24717

Published on
Nov 01, 2021
Research Description
The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.
Affected versions
Min -, max 1.7.6.
Status
vulnerable