CVE-2021-24725
MEDIUM 4.3EPSS 0.5%
The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments
- CVSS v3.1
- 4.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 0.49% chance of exploitation in the next 30 days, 40th percentile
- Published
- 2021-09-13
- Updated
- 2024-08-03
Proof-of-concept exploits (2)
- https://wpscan.com/vulnerability/01483284-57f5-4ae9-b5f1-ae26b623571f
- https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=292…