CVE-2021-24806

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
08/11/2021
Last modified:
09/11/2021

Description

The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gvectors:wpdiscuz:*:*:*:*:*:wordpress:*:* 7.3.4 (excluding)