Vulnerability Description
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to Stored Cross-Site Scripting issues
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wp Survey Plus Project | Wp Survey Plus | <= 1.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/78405609-2105-4011-b18e-1ba5f438972dExploitThird Party Advisory
- https://wpscan.com/vulnerability/78405609-2105-4011-b18e-1ba5f438972dExploitThird Party Advisory
FAQ
What is CVE-2021-24801?
CVE-2021-24801 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, d...
How severe is CVE-2021-24801?
CVE-2021-24801 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24801?
Check the references section above for vendor advisories and patch information. Affected products include: Wp Survey Plus Project Wp Survey Plus.