First published: Wed Jun 15 2022(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows changing the plugin settings.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Supsystic Photo Gallery | <1.15.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-36891 is medium.
The affected software for CVE-2021-36891 is the Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress.
CVE-2021-36891 allows changing the plugin settings by exploiting the Cross-Site Request Forgery (CSRF) vulnerability.
Yes, a fix is available for CVE-2021-36891. It is recommended to update to version 1.15.6 of the Photo Gallery by Supsystic plugin.
The CWE ID for CVE-2021-36891 is 352.