PT-2021-14290 · WordPress · Push Notifications For Wordpress
Ten Katouno
·
Published
2021-11-24
·
Updated
2021-11-29
·
CVE-2021-20846
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Push Notifications for WordPress (Lite) versions prior to 6.0.1
Description:
A cross-site request forgery (CSRF) issue allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web page.
Recommendations:
For versions prior to 6.0.1, update to version 6.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to administrative functions to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Push Notifications For Wordpress