PT-2021-15791 · WordPress · The Business Directory Plugin

0Xb9

·

Published

2021-05-05

·

Updated

2021-05-13

·

CVE-2021-24249

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Business Directory Plugin – Easy Listing Directories for WordPress versions prior to 5.11.2
Description The issue allows an attacker to perform a Cross-Site Request Forgery attack, enabling them to make a logged-in administrator export files. These files can then be downloaded by the attacker, potentially granting access to personally identifiable information (PII), such as email addresses and home addresses.
Recommendations For versions prior to 5.11.2, update to version 5.11.2 or later to resolve the issue.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24249

Affected Products

The Business Directory Plugin