First published: Mon Mar 07 2022(Updated: )
The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a logged in admin remove arbitrary posts from the blog via a CSRF attack, which will be put in the trash
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fatcatapps Easy Pricing Tables | <3.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-25098.
The affected software is the Pricing Tables WordPress Plugin WordPress plugin before version 3.1.3.
The severity rating of this vulnerability is medium.
Yes, attackers can make a logged-in admin remove arbitrary posts from the blog via a CSRF attack.
Yes, updating to version 3.1.3 of the Pricing Tables WordPress Plugin WordPress plugin will fix this vulnerability.