PT-2021-14234 · WordPress · Wordpress Email Template Designer - Wp Html Mail

Konan Nagashima

·

Published

2021-07-07

·

Updated

2021-07-10

·

CVE-2021-20779

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WordPress Email Template Designer - WP HTML Mail versions prior to 3.0.8
Description: A cross-site request forgery (CSRF) issue allows remote attackers to hijack the authentication of administrators via unspecified vectors. This affects administrators and could lead to unauthorized actions on behalf of the administrator.
Recommendations: For versions prior to 3.0.8, update to version 3.0.8 or later to resolve the issue. As a temporary workaround, consider implementing additional authentication checks or restricting access to sensitive areas of the WordPress Email Template Designer - WP HTML Mail to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20779

Affected Products

Wordpress Email Template Designer - Wp Html Mail