CVE-2021-24633
WordPress vulnerability analysis and mitigation

Overview

The vulnerability CVE-2021-24633 affects the WordPress Countdown Block plugin versions below 1.1.2. The issue was discovered and publicly disclosed on August 30, 2021. This security flaw involves a missing authorization in the AJAX action functionality of the plugin, which affects WordPress installations using the vulnerable versions of the Countdown Block plugin (WPScan).

Technical details

The vulnerability stems from a missing authorization check in the ebwriteblock_css AJAX action. The initial fix attempt in version 1.1.1 was incomplete, as it still allowed exploitation through a CSRF attack on an administrator due to a logic flaw. The vulnerability is classified as CWE-862 (Missing Authorization) and has been assigned a CVSS score of 6.5 (medium severity). This security issue falls under the OWASP Top 10 category A5: Broken Access Control (WPScan).

Impact

When exploited, this vulnerability allows any authenticated user, including those with minimal privileges such as Subscribers, to modify post contents that are displayed to users. This means that malicious actors with even basic authentication could potentially alter the content of posts on the affected WordPress site (WPScan).

Mitigation and workarounds

The vulnerability has been fixed in version 1.1.2 of the Countdown Block plugin. Site administrators are strongly advised to update to this version or later to protect against this security issue (WPScan).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13604HIGH7.2
  • security-malware-firewall
NoYesDec 09, 2025
CVE-2025-13642MEDIUM5.4
  • wp-user-avatar
NoYesDec 09, 2025
CVE-2025-13924MEDIUM4.3
  • advanced-product-fields-for-woocommerce
NoYesDec 09, 2025
CVE-2025-13071N/AN/A
  • custom-admin-menu
NoNoDec 09, 2025
CVE-2025-13070N/AN/A
  • csv-to-sorttable
NoNoDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management