CVE-2021-24641
The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrary image conversion
- Affected products
- Images To Webp
- Imagestowebp Project Images To Webp
- < 1.9
- Fix
- Available
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 0.5% (43th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2021-11-23
CVE-2021-24641 at NVD
1 known exploit for CVE-2021-24641
Proof-of-concept code and exploit modules indexed by Sploitus