CVE-2021-24806: wpDiscuz < 7.3.4 - Arbitrary Comment Addition/Edition/Deletion via CSRF
The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-24806.
What is the severity level of CVE-2021-24806?
The severity level of CVE-2021-24806 is medium with a severity value of 4.3.
What is the affected software for CVE-2021-24806?
The affected software for CVE-2021-24806 is the wpDiscuz WordPress plugin before version 7.3.4.
What is the potential impact of CVE-2021-24806?
The potential impact of CVE-2021-24806 is that an attacker can make logged in users such as admin edit and delete arbitrary comments, or the user who made the comment to edit it via a CSRF attack.
Is there a fix available for CVE-2021-24806?
Yes, the fix for CVE-2021-24806 is to update to version 7.3.4 or newer of the wpDiscuz WordPress plugin.