ZeroHour

CVE-2021-24725

PoC ×2
CVSS 3.1
4.3 medium
EPSS
<1%p41
Published
()
Modified
Description

The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments

Vendors
quantumcloud
Products
comment link remove and other comment tools
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.