PT-2021-14290 · WordPress · Push Notifications For Wordpress

Ten Katouno

·

Published

2021-11-24

·

Updated

2021-11-29

·

CVE-2021-20846

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Push Notifications for WordPress (Lite) versions prior to 6.0.1
Description: A cross-site request forgery (CSRF) issue allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web page.
Recommendations: For versions prior to 6.0.1, update to version 6.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to administrative functions to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20846

Affected Products

Push Notifications For Wordpress