Lucene search

K
cveWPScanCVE-2021-24636
HistorySep 20, 2021 - 10:15 a.m.

CVE-2021-24636

2021-09-2010:15:09
CWE-352
WPScan
web.nvd.nist.gov
24
print my blog
wordpress plugin
csrf
security vulnerability
nvd
cve-2021-24636

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

EPSS

0.001

Percentile

27.4%

The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link

Affected configurations

Nvd
Vulners
Node
print_my_blog_projectprint_my_blogRange<3.4.2wordpress
VendorProductVersionCPE
print_my_blog_projectprint_my_blog*cpe:2.3:a:print_my_blog_project:print_my_blog:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "product": "Print My Blog – Print, PDF, & eBook Converter WordPress Plugin",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "3.4.2",
        "status": "affected",
        "version": "3.4.2",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

EPSS

0.001

Percentile

27.4%

Related for CVE-2021-24636