PoC Index

CVE-2021-24989

MEDIUM 6.5EPSS 0.5%

The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
0.54% chance of exploitation in the next 30 days, 43th percentile
Published
2022-01-24
Updated
2024-08-03

Proof-of-concept exploits (1)

References

Related