CVE-2021-24806 Information

Description

The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding editing and deleting comments which could allow attacker to make logged in users such as admin edit and delete arbitrary comment or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Reference

https://wpscan.com/vulnerability/2746101e-e993-42b9-bd6f-dfd5544fa3fe

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

4.3

Share on: