CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It affects WordPress. Exploitation may require the attacker to be authenticated.
CVE
CVE-2021-24906
Severity
HIGH
CVSS
7.5
EPSS
1.49%
WordPress
Original NVD Description
The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request
Related CVEs
Other vulnerabilities affecting the same vendor(s)