ZeroHour

CVE-2021-24380

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p38
Published
()
Modified
Description

The Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing attackers to make logged in administrators change them to arbitrary values.

Vendors
shantz wordpress qotd project
Products
shantz wordpress qotd
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.