Cross-Site Request Forgery Vulnerability in DW Question & Answer Plugin for WordPress
CVE-2021-4408
4.3MEDIUM
What is CVE-2021-4408?
The DW Question & Answer plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) attack, primarily due to inadequate nonce validation in the update_answer() functionality. This vulnerability allows unauthorized attackers to exploit the system by tricking a site administrator into executing unintended actions, such as clicking a malicious link, thereby modifying answers to questions without proper authorization.
Affected Version(s)
DW Question & Answer 0 <= 1.5.8