Skip to content

Known CVE

WP Cerber < 8.9.3 - Broken Access Control

WP Cerber < 8.9.3 contains a bypass of /wp-json access control caused by improper handling of trailing '?' character, letting unauthorized users access protected REST API endpoints, exploit requires sending a request with a trailing '?'.

CVE-2021-37598

Medium2021CVSS 5.3CWE-863

cve2021 · wordpress · wp-cerber · access-control · rest-api · exposure · auth-bypass

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website