PT-2021-15718 · WordPress · Vm Backups

0Xb9

·

Published

2021-04-05

·

Updated

2021-04-09

·

CVE-2021-24172

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: VM Backups WordPress plugin versions 1.0 and earlier
Description: The issue allows attackers to make a logged-in user perform unwanted actions, such as generating backups of the database, plugins, and current data, due to the lack of CSRF checks.
Recommendations: For VM Backups WordPress plugin versions 1.0 and earlier, consider disabling the plugin until a patch is available to prevent exploitation. As a temporary workaround, restrict access to the plugin's functionality to minimize the risk of unwanted actions being performed by attackers.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24172

Affected Products

Vm Backups