CVE-2020-13642: CSRF
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The actionbuildercontent function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panelsdata $POST variable allows for malicious JavaScript to be executed in the victim's browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13642?
CVE-2020-13642 is classified as a high severity vulnerability due to its potential to allow unauthorized actions as an administrator.
How do I fix CVE-2020-13642?
To fix CVE-2020-13642, you should update the SiteOrigin Page Builder plugin to version 2.10.16 or later.
What type of attacks can CVE-2020-13642 enable?
CVE-2020-13642 could enable cross-site request forgery (CSRF) attacks, allowing an attacker to perform actions on behalf of an authenticated admin.
What versions of SiteOrigin Page Builder are affected by CVE-2020-13642?
CVE-2020-13642 affects all versions of SiteOrigin Page Builder before 2.10.16.
Is CVE-2020-13642 exploitable without user interaction?
Yes, CVE-2020-13642 is exploitable without user interaction since it does not involve nonce verification, which allows for crafted requests.