CVE-2021-24636
The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link
- Affected products
- Print My Blog
- Print My Blog Project Print My Blog
- < 3.4.2
- Fix
- Available
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 0.5% (42th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2021-09-20
CVE-2021-24636 at NVD
1 known exploit for CVE-2021-24636
Proof-of-concept code and exploit modules indexed by Sploitus