CVE-2021-24466
Verse-O-Matic <= 4.1.1 - CSRF to Stored XSS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the settings. Due to the lack of sanitisation in the settings and verses, this could also lead to Stored Cross-Site Scripting issues
El plugin de WordPress Verse-O-Matic versiones hasta 4.1.1, no presenta ninguna comprobación de tipo CSRF, permitiendo a atacantes hacer a unos administradores registrados realizar acciones no deseadas, como añadir/editar/borrar versos arbitrarios y cambiar la configuración. Debido a una falta de saneamiento en las configuraciones y versos, esto también podría conllevar a problemas de tipo Cross-Site Scripting Almacenado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-07-19 CVE Published
- 2024-03-22 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/37c7bdbb-f27f-47d3-9886-69d2e83d7581 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Verse-o-matic Project Search vendor "Verse-o-matic Project" | Verse-o-matic Search vendor "Verse-o-matic Project" for product "Verse-o-matic" | <= 4.1.1 Search vendor "Verse-o-matic Project" for product "Verse-o-matic" and version " <= 4.1.1" | wordpress |
Affected
|