PT-2021-22062 · WordPress · Nested Pages

Published

2021-08-30

·

Updated

2023-12-18

·

CVE-2021-38342

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nested Pages WordPress plugin versions <= 3.1.15
Description The issue allows attackers to perform Cross-Site Request Forgery attacks via the npBulkAction and npBulkEdit actions, enabling them to modify posts, including trashing or purging them, changing their status, reassigning ownership, and editing metadata.
Recommendations For Nested Pages WordPress plugin versions <= 3.1.15, update to a version greater than 3.1.15 to resolve the issue. As a temporary workaround, consider restricting access to the npBulkAction and npBulkEdit admin post actions to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2021-38342

Affected Products

Nested Pages