PT-2021-14234 · WordPress · Wordpress Email Template Designer - Wp Html Mail
Konan Nagashima
·
Published
2021-07-07
·
Updated
2021-07-10
·
CVE-2021-20779
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
WordPress Email Template Designer - WP HTML Mail versions prior to 3.0.8
Description:
A cross-site request forgery (CSRF) issue allows remote attackers to hijack the authentication of administrators via unspecified vectors. This affects administrators and could lead to unauthorized actions on behalf of the administrator.
Recommendations:
For versions prior to 3.0.8, update to version 3.0.8 or later to resolve the issue. As a temporary workaround, consider implementing additional authentication checks or restricting access to sensitive areas of the WordPress Email Template Designer - WP HTML Mail to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress Email Template Designer - Wp Html Mail