First published: Mon Oct 11 2021(Updated: )
The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tipsandtricks-hq Software License Manager | <4.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24711 is a CSRF vulnerability in the del_reistered_domains AJAX action of the Software License Manager WordPress plugin before version 4.5.1.
The severity of CVE-2021-24711 is high with a CVSS score of 8.8.
CVE-2021-24711 allows for CSRF attacks on the del_reistered_domains AJAX action of the Software License Manager WordPress plugin.
To fix CVE-2021-24711, update the Software License Manager plugin to version 4.5.1 or newer.
For additional information about CVE-2021-24711, refer to the references provided: https://jetpack.com/2021/09/14/csrf-vulnerability-found-in-software-license-manager-plugin/ and https://wpscan.com/vulnerability/3351bc30-e5ff-471f-8d1c-b1bcdf419937