CVE-2021-24711: Software License Manager < 4.5.1 - Arbitrary Domain Deletion via CSRF
The delreistereddomains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24711?
CVE-2021-24711 is a CSRF vulnerability in the del_reistered_domains AJAX action of the Software License Manager WordPress plugin before version 4.5.1.
What is the severity of CVE-2021-24711?
The severity of CVE-2021-24711 is high with a CVSS score of 8.8.
How does CVE-2021-24711 affect the Software License Manager plugin?
CVE-2021-24711 allows for CSRF attacks on the del_reistered_domains AJAX action of the Software License Manager WordPress plugin.
How can I fix CVE-2021-24711?
To fix CVE-2021-24711, update the Software License Manager plugin to version 4.5.1 or newer.
Is there any additional information about CVE-2021-24711?
For additional information about CVE-2021-24711, refer to the references provided: https://jetpack.com/2021/09/14/csrf-vulnerability-found-in-software-license-manager-plugin/ and https://wpscan.com/vulnerability/3351bc30-e5ff-471f-8d1c-b1bcdf419937