Vulnerability Description
The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a logged in admin remove arbitrary posts from the blog via a CSRF attack, which will be put in the trash
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fatcatapps | Easy Pricing Tables | < 3.1.3 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/960a634d-a88a-4d90-9ac3-7d24b1fe07feExploitThird Party Advisory
- https://wpscan.com/vulnerability/960a634d-a88a-4d90-9ac3-7d24b1fe07feExploitThird Party Advisory
FAQ
What is CVE-2021-25098?
CVE-2021-25098 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a logged in admin remove arbitrary posts from the blog ...
How severe is CVE-2021-25098?
CVE-2021-25098 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25098?
Check the references section above for vendor advisories and patch information. Affected products include: Fatcatapps Easy Pricing Tables.