PT-2022-9467 · WordPress · Core Tweaks Wp Setup
Francesco Carlucci
·
Published
2022-02-28
·
Updated
2022-03-07
·
CVE-2021-24803
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Core Tweaks WP Setup WordPress plugin versions through 4.1
Description
The issue allows an attacker to arbitrarily change the admin email or create another admin account due to the lack of CSRF protection, potentially leading to website takeover via CSRF attacks.
Recommendations
For Core Tweaks WP Setup WordPress plugin versions through 4.1, consider disabling the bulk setting feature until a patch is available to prevent arbitrary changes to admin email and creation of new admin accounts. Restrict access to the plugin's settings to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Core Tweaks Wp Setup