ZeroHour

CVE-2021-24500

PoC ×2
CVSS 3.1
8.1 high
EPSS
<1%p49
Published
()
Modified
Description

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.

Vendors
amentotech
Products
workreap
Ecosystems
WordPress
Weakness
CWE-283, CWE-284, CWE-862, CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.