Nested Pages <= 3.1.15 Cross-Site Request Forgery to Arbitrary Post Deletion and Modification
CVE-2021-38342
8.1HIGH
What is CVE-2021-38342?
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the npBulkAction
s and npBulkEdit
admin_post
actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata.
Affected Version(s)
Nested Pages 3.1.15