CVE-2021-24333

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
01/06/2021
Last modified:
07/11/2023

Description

The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its settings, not perform any validation and sanitisation on them, allowing attackers to make a logged in administrator set arbitrary XSS payloads in them.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:content_copy_protection_\&_prevent_image_save_project:content_copy_protection_\&_prevent_image_save:*:*:*:*:*:wordpress:*:* 1.3 (including)