ZeroHour

CVE-2021-38342

CVSS 3.1
8.1 high
EPSS
<1%p41
Published
()
Modified
Description

The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata.

Vendors
kylephillips
Products
nested pages
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.