Cross-Site Request Forgery in Process Steps Template Designer for WordPress
CVE-2021-4349
8.8HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 7 June 2023
Summary
The Process Steps Template Designer plugin for WordPress is susceptible to Cross-Site Request Forgery, allowing unauthenticated attackers to execute unauthorized actions by tricking site administrators into clicking on malicious links. This vulnerability affects versions up to and including 1.2.1. Users are encouraged to update to the latest version to safeguard against these exploits.
Affected Version(s)
Process Steps Template Designer * < 1.3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jerome Bruandet