CVE-2021-24636
Print My Blog < 3.4.2 - Plugin Deactivation via CSRF
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link
El plugin Print My Blog de WordPress versiones anteriores a 3.4.2, no aplica las comprobaciones de nonce (CSRF), lo que permite a atacantes hacer que los administradores que han iniciado sesiĆ³n desactiven el plugin Print My Blog y eliminen todos los datos guardados para ese plugin al engaƱarlos para que abran un enlace malicioso
The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-08-18 CVE Published
- 2024-04-26 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/db8ace7b-7a44-4620-9fe8-ddf0ad520f5e | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Print My Blog Project Search vendor "Print My Blog Project" | Print My Blog Search vendor "Print My Blog Project" for product "Print My Blog" | < 3.4.2 Search vendor "Print My Blog Project" for product "Print My Blog" and version " < 3.4.2" | wordpress |
Affected
|