CVE-2021-25072: NextScripts: Social Networks Auto-Poster < 4.3.25 - Arbitrary Post Deletion via CSRF
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-25072?
CVE-2021-25072 is considered a critical severity vulnerability as it allows an attacker to delete arbitrary posts by exploiting a CSRF attack.
How do I fix CVE-2021-25072?
To fix CVE-2021-25072, update the NextScripts: Social Networks Auto-Poster plugin to version 4.3.25 or later.
Who is affected by CVE-2021-25072?
Any WordPress site using the NextScripts: Social Networks Auto-Poster plugin prior to version 4.3.25 is affected by CVE-2021-25072.
What type of attack is associated with CVE-2021-25072?
CVE-2021-25072 is associated with Cross-Site Request Forgery (CSRF) attacks.
What is the nature of the vulnerability in CVE-2021-25072?
The nature of the vulnerability in CVE-2021-25072 is the lack of CSRF checks when deleting items, which can be exploited by authenticated attackers.