Description
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisioned under their old role after an administrator removes the role or disables the user's account.
Remediation
References
Related Vulnerabilities
WordPress Plugin Share and Follow 'admin.php' Cross-Site Scripting (1.80.3)
WordPress Plugin Soundy Background Music Cross-Site Scripting (3.1)
WordPress Plugin SagePay Server Gateway for WooCommerce Cross-Site Scripting (1.0.8)
WordPress Plugin AI ChatBot Information Disclosure (4.8.9)
WordPress Plugin WP Gravity Forms Insightly Cross-Site Scripting (1.0.6)