Cross-Site Request Forgery in Process Steps Template Designer for WordPress
CVE-2021-4349

8.8HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
7 June 2023

Summary

The Process Steps Template Designer plugin for WordPress is susceptible to Cross-Site Request Forgery, allowing unauthenticated attackers to execute unauthorized actions by tricking site administrators into clicking on malicious links. This vulnerability affects versions up to and including 1.2.1. Users are encouraged to update to the latest version to safeguard against these exploits.

Affected Version(s)

Process Steps Template Designer * < 1.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jerome Bruandet
.