CVE-2021-24328
Last modified
CVE-2021-24328 is a medium-severity vulnerability rated 6.2/10 on the CVSS scale. The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators change the plugin's settings to arbitrary values, and set XSS payloads on them as well. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators change the plugin's settings to arbitrary values, and set XSS payloads on them as well
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Clogica | Wp Login Security And History | <= 1.0 |
References
- https://m0ze.ru/exploit/csrf-wp-login-security-and-history-v1.0.htmlExploit, Third Party Advisory
- https://wpscan.com/vulnerability/eeb41d7b-8f9e-4a12-b65f-f310f08e4aceExploit, Third Party Advisory
- https://m0ze.ru/exploit/csrf-wp-login-security-and-history-v1.0.htmlExploit, Third Party Advisory
- https://wpscan.com/vulnerability/eeb41d7b-8f9e-4a12-b65f-f310f08e4aceExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-24328?
How severe is CVE-2021-24328?
How do I fix CVE-2021-24328?
Are you affected by CVE-2021-24328?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
