CVE-2021-25010

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
28/02/2022
Last modified:
08/03/2022

Description

The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting issues

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:postsnippets:post_snippets:*:*:*:*:*:wordpress:*:* 3.1.4 (excluding)