CVE-2021-25092: Link Library < 7.2.8 - Library Settings Reset via CSRF
Published Feb 1, 2022
·Updated
The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack
Affected Software
2 affected components
Ylefebvre Link Library Wordpress<7.2.8
Link Library Project Link Library Wordpress<7.2.8
Event History
Feb 1, 2022
CVE Published
via MITRE·12:21 PM
Data Sourced
via MITRE·12:21 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25092?
CVE-2021-25092 has a medium severity rating due to the potential for unauthorized changes to library settings through CSRF attacks.
2
How do I fix CVE-2021-25092?
To fix CVE-2021-25092, update the Link Library WordPress plugin to version 7.2.8 or later.
3
What type of attack does CVE-2021-25092 allow?
CVE-2021-25092 allows attackers to execute CSRF attacks to reset arbitrary library settings on a compromised WordPress site.
4
Which versions of the Link Library plugin are affected by CVE-2021-25092?
CVE-2021-25092 affects all versions of the Link Library plugin prior to 7.2.8.
5
Who is at risk from CVE-2021-25092?
Administrators of WordPress sites using the affected versions of the Link Library plugin are at risk of unauthorized settings changes.