Beveiligingsadvies

CVE-2021-24806

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-11-08 17:35:24
Laatst bijgewerkt 2024-08-03 19:42:17
Toegewezen door WPScan
CVSS-score geen score
Status PUBLISHED

Beschrijving

The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment.