Cross-Site Request Forgery Vulnerability in Style Kits Plugin for WordPress
CVE-2021-4401
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 July 2023
What is CVE-2021-4401?
The Style Kits plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) attack due to improper nonce validation within the update_posts_stylekit() function. This vulnerability enables unauthenticated attackers to potentially alter style kits for posts by exploiting the administrator's action through a deceptive link, highlighting the importance of robust nonce checks to secure action calls.
Affected Version(s)
Style Kits β Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns 0 <= 1.8.0