Vulnerability Description
The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrary publication
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Creativityjuice | Labtools | <= 1.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/67f5beb8-2cb0-4b43-87c7-dead9c005f9cThird Party Advisory
- https://wpscan.com/vulnerability/67f5beb8-2cb0-4b43-87c7-dead9c005f9cThird Party Advisory
FAQ
What is CVE-2021-25097?
CVE-2021-25097 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrar...
How severe is CVE-2021-25097?
CVE-2021-25097 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25097?
Check the references section above for vendor advisories and patch information. Affected products include: Creativityjuice Labtools.