Print My Blog < 3.4.2 - Plugin Deactivation via CSRF
CVE-2021-24636

8.1HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
20 September 2021

Summary

The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link

Affected Version(s)

Print My Blog – Print, PDF, & eBook Converter WordPress Plugin 3.4.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

apple502j
.