CVE-2021-36891: WordPress Photo Gallery by Supsystic plugin <= 1.15.5 - Cross-Site Request Forgery (CSRF) leading to Plugin Settings Change
Published Jun 15, 2022
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows changing the plugin settings.
Affected Software
1 affected component
Supsystic Photo Gallery Wordpress<1.15.6
Event History
Jun 15, 2022
CVE Published
via MITRE·07:16 PM
Data Sourced
via MITRE·07:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-36891?
The severity of CVE-2021-36891 is medium.
2
What is the affected software for CVE-2021-36891?
The affected software for CVE-2021-36891 is the Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress.
3
How can I change the plugin settings after exploiting CVE-2021-36891?
CVE-2021-36891 allows changing the plugin settings by exploiting the Cross-Site Request Forgery (CSRF) vulnerability.
4
Is there a fix available for CVE-2021-36891?
Yes, a fix is available for CVE-2021-36891. It is recommended to update to version 1.15.6 of the Photo Gallery by Supsystic plugin.
5
What is the CWE ID for CVE-2021-36891?
The CWE ID for CVE-2021-36891 is 352.