First published: Wed Nov 17 2021(Updated: )
The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make a logged in admin or editor change taxonomy colors via a CSRF attack
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gesundheit-bewegt Colorful Categories | <2.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-24802.
The severity of CVE-2021-24802 is medium (6.5).
CVE-2021-24802 allows attackers to make a logged in admin or editor change taxonomy colors via a CSRF attack in the Colorful Categories WordPress plugin.
To fix CVE-2021-24802, update the Colorful Categories WordPress plugin to version 2.0.15 or higher, which enforces nonce checks.
Yes, you can find more information about CVE-2021-24802 at this reference: https://wpscan.com/vulnerability/d92db61f-341c-4f3f-b962-326194ddbd1e