Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-19840
HistoryJan 26, 2022 - 12:00 a.m.

WordPress Qubely plugin cross-site request forgery vulnerability

2022-01-2600:00:00
China National Vulnerability Database
www.cnvd.org.cn
13
wordpress
qubely plugin
cross-site request forgery
php
mysql
ajax operation
authorization
csrf
arbitrary posts

EPSS

0.001

Percentile

21.2%

WordPress is the WordPress Foundation’s set of blogging platforms developed using the PHP language. The platform supports setting up personal blog sites on PHP and MySQL servers. cross-site request forgery vulnerability exists in versions prior to 1.7.8 of the Qubely plugin for WordPress, which stems from the lack of authorization and CSRF checks on the Qubely_delete_saved_block AJAX operation. An attacker could use this vulnerability to delete arbitrary posts.

EPSS

0.001

Percentile

21.2%