Vulnerability Description
The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged in user overwrite or create arbitrary user metadata on the victim’s account once visited. If exploited, this bug can be used to overwrite the “wp_capabilities” meta, which contains the affected user account’s roles and privileges. Doing this would essentially lock them out of the site, blocking them from accessing paid content.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Patreon | Patreon Wordpress | < 1.7.0 |
Related Weaknesses (CWE)
References
- https://jetpack.com/2021/03/26/vulnerabilities-found-in-patreon-wordpress-pluginExploitThird Party Advisory
- https://wpscan.com/vulnerability/2deefa2d-3043-42e5-afef-a42c37703531Third Party Advisory
- https://jetpack.com/2021/03/26/vulnerabilities-found-in-patreon-wordpress-pluginExploitThird Party Advisory
- https://wpscan.com/vulnerability/2deefa2d-3043-42e5-afef-a42c37703531Third Party Advisory
FAQ
What is CVE-2021-24230?
CVE-2021-24230 is a vulnerability with a CVSS score of 8.1 (HIGH). The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged in user overwrite or create arbitrary user...
How severe is CVE-2021-24230?
CVE-2021-24230 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24230?
Check the references section above for vendor advisories and patch information. Affected products include: Patreon Patreon Wordpress.