Ver todas as ameaças

CVE-2021-24572

Alvo: Não informado

Descrição

The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in admins delete arbitrary posts

Software
Não informado
Tipo Software
Plugin
CVE
CVE-2021-24572
Tags
Nâo informado
Data de publicação
01/11/2021
Última atualização
08/12/2024
Pontuação em CVSS 3.0
4.3
Médio
Rolar para cima