ZeroHour

CVE-2021-24989

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p44
Published
()
Modified
Description

The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog

Vendors
wpplugin
Products
accept donations with paypal
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.