CVE-2021-24725

The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments
Configurations

Configuration 1 (hide)

cpe:2.3:a:quantumcloud:comment_link_remove_and_other_comment_tools:*:*:*:*:*:wordpress:*:*

History

23 Sep 2021, 15:22

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 4.3
CPE cpe:2.3:a:quantumcloud:comment_link_remove_and_other_comment_tools:*:*:*:*:*:wordpress:*:*
References (MISC) https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=29225 - (MISC) https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=29225 - Exploit, Third Party Advisory
References (MISC) https://wpscan.com/vulnerability/01483284-57f5-4ae9-b5f1-ae26b623571f - (MISC) https://wpscan.com/vulnerability/01483284-57f5-4ae9-b5f1-ae26b623571f - Exploit, Third Party Advisory

13 Sep 2021, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-13 18:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-24725

Mitre link : CVE-2021-24725

CVE.ORG link : CVE-2021-24725


JSON object : View

Products Affected

quantumcloud

  • comment_link_remove_and_other_comment_tools
CWE
CWE-352

Cross-Site Request Forgery (CSRF)