CVE-2021-24446: Remove Footer Credit < 1.0.6 - CSRF to Stored Cross-Site Scripting
Published Feb 14, 2022
·Updated
The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored XSS issue as well due to the lack of sanitisation
Affected Software
1 affected component
WPChill Remove Footer Credit Wordpress<1.0.6
Event History
Feb 14, 2022
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-24446.
2
What is the severity of CVE-2021-24446?
The severity of CVE-2021-24446 is medium.
3
What is the affected software of CVE-2021-24446?
The affected software of CVE-2021-24446 is the Remove Footer Credit WordPress plugin before version 1.0.6.
4
What is the reference for CVE-2021-24446?
The reference for CVE-2021-24446 is [https://wpscan.com/vulnerability/be55131b-d9f2-4ac1-b667-c544c066887f](https://wpscan.com/vulnerability/be55131b-d9f2-4ac1-b667-c544c066887f).
5
What is the CWE of CVE-2021-24446?
The CWE of CVE-2021-24446 is CWE-79 and CWE-352.