Vulnerability Description
The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored XSS issue as well due to the lack of sanitisation
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpchill | Remove Footer Credit | < 1.0.6 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/be55131b-d9f2-4ac1-b667-c544c066887fExploitThird Party Advisory
- https://wpscan.com/vulnerability/be55131b-d9f2-4ac1-b667-c544c066887fExploitThird Party Advisory
FAQ
What is CVE-2021-24446?
CVE-2021-24446 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored XS...
How severe is CVE-2021-24446?
CVE-2021-24446 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24446?
Check the references section above for vendor advisories and patch information. Affected products include: Wpchill Remove Footer Credit.