Cross-Site Request Forgery in ElasticPress Plugin for WordPress
CVE-2021-4405
4.3MEDIUM
Summary
The ElasticPress plugin for WordPress is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in the epio_send_autosuggest_allowed() function. This vulnerability may allow unauthorized attackers to leverage forged requests to manipulate autosuggest features on elasticpress[.]io if they deceive a site administrator into executing an action, such as clicking a malicious link. This raises significant security concerns for WordPress sites utilizing ElasticPress, as it opens the door for unauthorized actions without proper authentication.
Affected Version(s)
ElasticPress * <= 3.5.3
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jerome Bruandet