CVE-2021-4349: Process Steps Template Designer <= 1.2.1 - Cross-Site Request Forgery
The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for the Process Steps Template Designer plugin for WordPress?
The vulnerability ID for the Process Steps Template Designer plugin for WordPress is CVE-2021-4349.
What is the severity level of CVE-2021-4349?
CVE-2021-4349 has a severity level of 8.8 (high).
What is the affected software for CVE-2021-4349?
The affected software for CVE-2021-4349 is the Process Steps Template Designer plugin for WordPress (up to and including version 1.2.1).
How can an attacker exploit CVE-2021-4349?
An unauthenticated attacker can exploit CVE-2021-4349 by conducting unspecified attacks via forged requests, provided they can trick a site administrator into performing certain actions.
Are there any references for CVE-2021-4349?
Yes, you can find references for CVE-2021-4349 at the following URLs: [Reference 1](https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-1/), [Reference 2](https://plugins.trac.wordpress.org/changeset/2473649/), [Reference 3](https://www.wordfence.com/threat-intel/vulnerabilities/id/2acd40d5-8a9c-4ca8-9c89-5bf639b1c66c?source=cve).