CVE-2021-24466
The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the settings. Due to the lack of sanitisation in the settings and verses, this could also lead to Stored Cross-Site Scripting issues
- Affected products
- Verse-O-Matic
- Verse-o-matic Project Verse-o-matic
- ≤ 4.1.1
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 0.4% (35th percentile)
- Weakness
- CWE-79, CWE-352
- NVD status
- Modified
- Published
- 2021-08-16
CVE-2021-24466 at NVD
1 known exploit for CVE-2021-24466
Proof-of-concept code and exploit modules indexed by Sploitus