ZeroHour

CVE-2021-24446

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p26
Published
()
Modified
Description

The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored XSS issue as well due to the lack of sanitisation

Vendors
wpchill
Products
remove footer credit
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.