CVE-2021-47830

Severity CVSS v4.0:
MEDIUM
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
21/01/2026
Last modified:
06/03/2026

Description

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not directly enable remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:get-simple:getsimplecms:1.1.1:*:*:*:*:*:*:*