CVE-2021-24380

T

he Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing attackers to make logged in administrators change them to arbitrary values.

Configurations

Configuration 1 (hide)

cpe:2.3:a:shantz_wordpress_qotd_project:shantz_wordpress_qotd:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 05:52

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/1dd0f9a8-22ab-4ecc-a925-605822739000 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/1dd0f9a8-22ab-4ecc-a925-605822739000 - Exploit, Third Party Advisory

Information

Published : 2021-08-16 11:15

Updated : 2024-11-21 05:52


NVD link : CVE-2021-24380

Mitre link : CVE-2021-24380

CVE.ORG link : CVE-2021-24380


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)