PT-2022-9447 · WordPress · Orange Form

Francesco Carlucci

·

Published

2022-02-28

·

Updated

2022-03-07

·

CVE-2021-24688

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Orange Form WordPress plugin versions prior to 1.0.2
Description The issue concerns a lack of authorization and CSRF checks in AJAX calls within the plugin. Specifically, the or delete filed AJAX call is accessible to both unauthenticated and authenticated users, potentially allowing attackers to delete arbitrary posts. Additionally, the plugin does not verify if a post belongs to the user or if they are authorized to perform actions on it.
Recommendations For Orange Form WordPress plugin versions prior to 1.0.2, update to version 1.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the or delete filed AJAX call to prevent unauthorized post deletion.

Exploit

Fix

Improper Access Control

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24688

Affected Products

Orange Form