CVE-2021-25098

All FrameworksWordPressCWE-352CVE-2021-25098

CVE-2021-25098

State: PUBLISHED · Published: 2022-03-07 · Updated: 2024-08-03 · Assigner: WPScan
Description
The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a logged in admin remove arbitrary posts from the blog via a CSRF attack, which will be put in the trash
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2021/25xxx/CVE-2021-25098.json