CVE-2021-25084 describes an authorization bypass vulnerability in the Advanced Cron Manager and Advanced Cron Manager Pro WordPress plugins prior to versions 2.4.2 and 2.5.3, respectively. Authenticated users, even those with subscriber privileges, could exploit this flaw due to missing authorization checks in certain AJAX actions. This allowed them to add or remove cron events and schedules, potentially disrupting website operations. The vulnerability has a CVSS v3.1 score of 4.3 (Medium), indicating a network-based attack with low attack complexity and requiring low privileges, resulting in a low impact on integrity and no impact on confidentiality or availability. While the potential impact is limited to integrity, the ease of exploitation by any authenticated user makes it a concern. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention from researchers or threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.2CPE matchmatch criteria | cpe:2.3:a:bracketspace:advanced_cron_manager:*:*:*:*:-:wordpress:*:* | ||
< 2.5.3CPE matchmatch criteria | cpe:2.3:a:bracketspace:advanced_cron_manager:*:*:*:*:pro:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.