PT-2022-9467 · WordPress · Core Tweaks Wp Setup

Francesco Carlucci

·

Published

2022-02-28

·

Updated

2022-03-07

·

CVE-2021-24803

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Core Tweaks WP Setup WordPress plugin versions through 4.1
Description The issue allows an attacker to arbitrarily change the admin email or create another admin account due to the lack of CSRF protection, potentially leading to website takeover via CSRF attacks.
Recommendations For Core Tweaks WP Setup WordPress plugin versions through 4.1, consider disabling the bulk setting feature until a patch is available to prevent arbitrary changes to admin email and creation of new admin accounts. Restrict access to the plugin's settings to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24803

Affected Products

Core Tweaks Wp Setup