WordPress · Push Notifications For Wordpress · CVE-2021-20846
Name of the Vulnerable Software and Affected Versions:
Push Notifications for WordPress (Lite) versions prior to 6.0.1
Description:
A cross-site request forgery (CSRF) issue allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web page.
Recommendations:
For versions prior to 6.0.1, update to version 6.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to administrative functions to minimize the risk of exploitation.