CVE-2021-24636 Information
Jun 07, 2022
cve
Description
The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Reference
https://wpscan.com/vulnerability/db8ace7b-7a44-4620-9fe8-ddf0ad520f5e
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.1
Share on: