Vulnerability Description
The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings, or perform such attack via CSRF. Furthermore, due to the lack of escaping, this could lead to Stored Cross-Site Scripting issues
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpdevart | Duplicate Page Or Post | < 1.5.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/db5a0431-af4d-45b7-be4e-36b6c90a601bExploitThird Party Advisory
- https://wpscan.com/vulnerability/db5a0431-af4d-45b7-be4e-36b6c90a601bExploitThird Party Advisory
FAQ
What is CVE-2021-25075?
CVE-2021-25075 is a vulnerability with a CVSS score of 3.5 (LOW). The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authe...
How severe is CVE-2021-25075?
CVE-2021-25075 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25075?
Check the references section above for vendor advisories and patch information. Affected products include: Wpdevart Duplicate Page Or Post.