CVE-2021-38312 is an incorrect authorization vulnerability affecting the Gutenberg Template Library & Redux Framework plugin for WordPress versions up to 4.2.11. The flaw allows lower-privileged users, such as contributors, to install arbitrary plugins from the WordPress repository and edit any post due to an insufficient permissions check in the REST API. With a CVSS score of 6.5 (Medium), this vulnerability has a low attack complexity and can lead to high integrity impacts without requiring user interaction. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2.11CPE matchmatch criteria | cpe:2.3:a:redux:gutenberg_template_library_\&_redux_framework:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.