WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://github.com/fireeye/Vulnerability-Disclosures | third party advisory |
https://github.com/fireeye/Vulnerability-Disclosures/blob/master/FEYE-2021-0024/FEYE-2021-0024.md | third party advisory exploit |