CVE-2021-39353

The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the ajax_add_form function found in the ~/includes/class-form.php file which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 2.1.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:easyregistrationforms:easy_registration_forms:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 06:19

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/browser/easy-registration-forms/tags/2.1.1/includes/class-form.php#L256 - Third Party Advisory () https://plugins.trac.wordpress.org/browser/easy-registration-forms/tags/2.1.1/includes/class-form.php#L256 - Third Party Advisory
References () https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39353 - Third Party Advisory () https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39353 - Third Party Advisory

24 Nov 2021, 16:23

Type Values Removed Values Added
References (MISC) https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39353 - (MISC) https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39353 - Third Party Advisory
References (MISC) https://plugins.trac.wordpress.org/browser/easy-registration-forms/tags/2.1.1/includes/class-form.php#L256 - (MISC) https://plugins.trac.wordpress.org/browser/easy-registration-forms/tags/2.1.1/includes/class-form.php#L256 - Third Party Advisory
CVSS v2 : unknown
v3 : 8.8
v2 : 6.8
v3 : 8.8
CPE cpe:2.3:a:easyregistrationforms:easy_registration_forms:*:*:*:*:*:wordpress:*:*

19 Nov 2021, 16:37

Type Values Removed Values Added
New CVE

Information

Published : 2021-11-19 16:15

Updated : 2024-11-21 06:19


NVD link : CVE-2021-39353

Mitre link : CVE-2021-39353

CVE.ORG link : CVE-2021-39353


JSON object : View

Products Affected

easyregistrationforms

  • easy_registration_forms
CWE
CWE-352

Cross-Site Request Forgery (CSRF)