AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-24188

HIGH · CVSS 8.8 EPSS 1.32%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-05-14 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-24188
Severity
HIGH
CVSS
8.8
EPSS
1.32%
WordPress

Original NVD Description

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.