---
title: "CVE-2021-29450"
canonical: "https://kb.cynergy.app/space/MD/923664662/CVE-2021-29450"
format: markdown
---
**Description**

Certain versions of [Debian Linux](https://cve.report/software/debian/debian_linux) from [Debian](https://cve.report/vendor/debian) contain the following vulnerability:

Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with the older affected versions via minor releases. It's strongly recommended that you keep auto-updates enabled to receive the fix.

**Published On**

04/15/2021

**Updated On**

04/23/2021

**Trending**

FALSE

**CWE**

<u>[CWE-200](http://cwe.mitre.org/data/definitions/200.html)</u>

**Exploit**

 

**Mitigation:**

![image](media://038b7cb0-c2b1-4627-9b6c-848592198cf0)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

- It's strongly recommended that you keep auto-updates enabled to receive the fix.
- [178554](https://cve.report/qid/178554) Debian Security Update for wordpress (DLA 2630-1)
- [178560](https://cve.report/qid/178560) Debian Security Update for wordpress (DSA 4896-1)
- [180560](https://cve.report/qid/180560) Debian Security Update for wordpress (CVE-2021-29450)
- [730052](https://cve.report/qid/730052) WordPress Prior to 5.7.1 Multiple Vulnerabilities

**References**

|  |  |  |
| --- | --- | --- |
| [SECURITY] [DLA 2630-1] wordpress security update | [http://lists.debian.org](http://lists.debian.org)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Debian -- Security Information -- DSA-4896-1 wordpress | [http://www.debian.org](http://www.debian.org)   
<span style="color: #ffffff">**Depreciated Link**</span>  
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| News – Security – [WordPress.org](http://WordPress.org) | [http://wordpress.org](http://wordpress.org)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| WordPress: Authenticated disclosure of password-protected posts and pages · Advisory · WordPress/wordpress-develop · GitHub | [http://github.com](http://github.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |